VulnerabilityModified
CVE-2009-1173
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were…
LOW 2.1EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34131
- http://secunia.com/advisories/34461Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463Patch
- http://www.securityfocus.com/bid/34259
- http://www.vupen.com/english/advisories/2009/0854Patch, Vendor Advisory
- http://secunia.com/advisories/34131
- http://secunia.com/advisories/34461Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463Patch
- http://www.securityfocus.com/bid/34259
- http://www.vupen.com/english/advisories/2009/0854Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.