MEDIUM
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests
Published Jul 5, 2009
6.4
MEDIUMCVSS 2.0
EPSS 2.02%
Description
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
Affected products
No data.
OR
- 6.1
- 6.1.0
- 6.1.0.1
- 6.1.0.2
- 6.1.0.3
- 6.1.0.4
- 6.1.0.5
- 6.1.0.6
- 6.1.0.7
- 6.1.0.8
- 6.1.0.9
- 6.1.0.10
- 6.1.0.11
- 6.1.0.12
- 6.1.0.13
- 6.1.0.14
- 6.1.0.15
- 6.1.0.16
- 6.1.0.17
- 6.1.0.18
- 6.1.0.19
- 6.1.0.20
- 6.1.0.21
- 6.1.0.22
- 6.1.0.23
- 6.1.1
- 6.1.13
- 6.1.14
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www-01.ibm.com/support/docview.wss?uid=swg27007951 x_refsource_CONFIRM
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK84015 vendor-advisoryx_refsource_AIXAPAR
- http://www.securityfocus.com/bid/35741 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0901 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51490 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg27007951 | x_refsource_CONFIRM | |
| http://www-1.ibm.com/support/docview.wss?uid=swg1PK84015 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www.securityfocus.com/bid/35741 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0901 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51490 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 5, 2009
Updated Aug 7, 2024
Reserved Mar 14, 2009
Link CVE-2009-0904
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-0901 Assigner mitre
Published Jul 5, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-0901