HIGH
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application
Published Jun 24, 2009
7.5
HIGHCVSS 2.0
EPSS 2.16%
Description
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
Affected products
No data.
OR
- 6.1
- 6.1.0
- 6.1.0.0
- 6.1.0.1
- 6.1.0.2
- 6.1.0.3
- 6.1.0.4
- 6.1.0.5
- 6.1.0.6
- 6.1.0.7
- 6.1.0.8
- 6.1.0.9
- 6.1.0.10
- 6.1.0.11
- 6.1.0.12
- 6.1.0.13
- 6.1.0.14
- 6.1.0.15
- 6.1.0.16
- 6.1.0.17
- 6.1.0.18
- 6.1.0.19
- 6.1.0.20
- 6.1.0.21
- 6.1.0.22
- 6.1.0.23
- 6.1.0.24
- 7.0
- 7.0.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (6)
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK72138 vendor-advisoryx_refsource_AIXAPAR
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK81944 vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK87767 vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory
- http://www.securityfocus.com/bid/35594 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0900 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51293 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://www-1.ibm.com/support/docview.wss?uid=swg1PK72138 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www-1.ibm.com/support/docview.wss?uid=swg1PK81944 | vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory | |
| http://www-1.ibm.com/support/docview.wss?uid=swg1PK87767 | vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory | |
| http://www.securityfocus.com/bid/35594 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0900 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51293 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2009
Updated Aug 7, 2024
Reserved Mar 14, 2009
Link CVE-2009-0903
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-0900 Assigner mitre
Published Jun 24, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-0900