CVE-2009-0434
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413.
- CVSS 2.0
- 1.9 LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg27006876
- http://www-01.ibm.com/support/docview.wss?uid=swg27007951
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK63886
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK79230
- http://www.securityfocus.com/bid/33700
- http://www.vupen.com/english/advisories/2009/0423
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48524
- http://www-01.ibm.com/support/docview.wss?uid=swg27006876
- http://www-01.ibm.com/support/docview.wss?uid=swg27007951
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK63886
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK79230
- http://www.securityfocus.com/bid/33700
- http://www.vupen.com/english/advisories/2009/0423
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48524
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.