VulnerabilityModified
CVE-2009-2749
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
MEDIUM 6.4EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- ibm/websphere application server · ibm/communications enabled applications
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM00435
- http://www-01.ibm.com/support/docview.wss?uid=swg27017328Patch
- http://www.securityfocus.com/bid/37392
- http://www.vupen.com/english/advisories/2009/3598
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54494
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM00435
- http://www-01.ibm.com/support/docview.wss?uid=swg27017328Patch
- http://www.securityfocus.com/bid/37392
- http://www.vupen.com/english/advisories/2009/3598
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54494
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.