SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-2749

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

MEDIUM 6.4EPSS 1.15%

Does this matter?

Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.

Description

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
ibm/websphere application server · ibm/communications enabled applications
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.