CVE-2009-0899

EUVD-2009-0896
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
ibmintegrated_solutions_console
6.0.1
ibmwebsphere_application_server
6.1 ≤
𝑥
≤ 6.1.0.24
ibmwebsphere_application_server
7.0 ≤
𝑥
≤ 7.0.0.4
ibmwebsphere_portal
5.1 ≤
𝑥
< 6.0.0.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration