CVE-2009-0434
10.02.2009, 22:30
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413.Enginsight
| Vendor | Product | Version | 
|---|---|---|
| ibm | websphere_application_server | 6.0  | 
| ibm | websphere_application_server | 6.0.0.1  | 
| ibm | websphere_application_server | 6.0.0.2  | 
| ibm | websphere_application_server | 6.0.0.3  | 
| ibm | websphere_application_server | 6.0.1  | 
| ibm | websphere_application_server | 6.0.1.1  | 
| ibm | websphere_application_server | 6.0.1.2  | 
| ibm | websphere_application_server | 6.0.1.3  | 
| ibm | websphere_application_server | 6.0.1.5  | 
| ibm | websphere_application_server | 6.0.1.7  | 
| ibm | websphere_application_server | 6.0.1.9  | 
| ibm | websphere_application_server | 6.0.1.11  | 
| ibm | websphere_application_server | 6.0.1.13  | 
| ibm | websphere_application_server | 6.0.1.15  | 
| ibm | websphere_application_server | 6.0.1.17  | 
| ibm | websphere_application_server | 6.0.2  | 
| ibm | websphere_application_server | 6.0.2.1  | 
| ibm | websphere_application_server | 6.0.2.2  | 
| ibm | websphere_application_server | 6.0.2.3  | 
| ibm | websphere_application_server | 6.0.2.4  | 
| ibm | websphere_application_server | 6.0.2.5  | 
| ibm | websphere_application_server | 6.0.2.6  | 
| ibm | websphere_application_server | 6.0.2.7  | 
| ibm | websphere_application_server | 6.0.2.9  | 
| ibm | websphere_application_server | 6.0.2.11  | 
| ibm | websphere_application_server | 6.0.2.13  | 
| ibm | websphere_application_server | 6.0.2.15  | 
| ibm | websphere_application_server | 6.0.2.17  | 
| ibm | websphere_application_server | 6.0.2.19  | 
| ibm | websphere_application_server | 6.0.2.22  | 
| ibm | websphere_application_server | 6.0.2.23  | 
| ibm | websphere_application_server | 6.0.2.24  | 
| ibm | websphere_application_server | 6.0.2.25  | 
| ibm | websphere_application_server | 6.0.2.27  | 
| ibm | websphere_application_server | 6.0.2.28  | 
| ibm | websphere_application_server | 6.0.2.29  | 
| ibm | websphere_application_server | 6.0.2.30  | 
| ibm | websphere_application_server | 6.0.2.31  | 
| ibm | websphere_application_server | 6.1  | 
| ibm | websphere_application_server | 6.1.0  | 
| ibm | websphere_application_server | 6.1.0.0  | 
| ibm | websphere_application_server | 6.1.0.1  | 
| ibm | websphere_application_server | 6.1.0.2  | 
| ibm | websphere_application_server | 6.1.0.10  | 
| ibm | websphere_application_server | 6.1.0.11  | 
| ibm | websphere_application_server | 6.1.0.12  | 
| ibm | websphere_application_server | 6.1.0.13  | 
| ibm | websphere_application_server | 6.1.0.14  | 
| ibm | websphere_application_server | 6.1.0.15  | 
| ibm | websphere_application_server | 6.1.0.16  | 
| ibm | websphere_application_server | 6.1.0.17  | 
| ibm | websphere_application_server | 6.1.0.18  | 
| ibm | websphere_application_server | 6.1.0.19  | 
| ibm | websphere_application_server | 6.1.0.20  | 
| ibm | websphere_application_server | 6.1.0.21  | 
| ibm | websphere_application_server | 7.0  | 
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References