CVE-2009-0906
- EPSS 0.34%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access vi...
CVE-2009-2085
- EPSS 0.32%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrict...
CVE-2009-2087
- EPSS 0.04%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfusca...
CVE-2009-2088
- EPSS 0.55%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass ...
CVE-2009-2089
- EPSS 0.21%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by readin...
- EPSS 0.36%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) ...
- EPSS 0.22%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVE-2009-2092
- EPSS 0.3%
- Published 13.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
- EPSS 7.44%
- Published 14.07.2009 23:30:00
- Last modified 09.04.2025 00:30:58
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLog...
CVE-2009-0904
- EPSS 0.25%
- Published 05.07.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify ...