[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256369

 
 

909

 
 

199183

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0506Date: (C)2009-02-25   (M)2023-12-22


Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.2
Exploit Score: 1.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-33884
PK71143
http://www-01.ibm.com/support/docview.wss?uid=swg27006876
websphere-zos-csiv2-unspecified(48886)

CPE    6
cpe:/a:ibm:websphere_application_server:5.1.0
cpe:/a:ibm:websphere_application_server:6.0.2.24
cpe:/a:ibm:websphere_application_server:6.0.2.22
cpe:/a:ibm:websphere_application_server:6.0.2
...

© SecPod Technologies