VulnerabilityModified
CVE-2009-0906
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via…
MEDIUM 6.5EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36306Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27015429Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52074
- http://secunia.com/advisories/36306Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27015429Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52074
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.