CVE-2009-0899
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration…
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/integrated solutions console · ibm/websphere application server · ibm/websphere portal
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21375859Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK78134Vendor Advisory
- http://www.securityfocus.com/bid/35406Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50882Third Party Advisory, VDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg21375859Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK78134Vendor Advisory
- http://www.securityfocus.com/bid/35406Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50882Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.