CVE-2009-0440

EUVD-2009-0444
IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
ibmwebsphere_partner_gateway
6.0.0
ibmwebsphere_partner_gateway
6.0.0.1
ibmwebsphere_partner_gateway
6.0.0.2
ibmwebsphere_partner_gateway
6.0.0.3
ibmwebsphere_partner_gateway
6.0.0.4
ibmwebsphere_partner_gateway
6.0.0.5
ibmwebsphere_partner_gateway
6.0.0.6
ibmwebsphere_partner_gateway
6.0.0.7
𝑥
= Vulnerable software versions