CVE-2009-0437
published 2009-02-10CVE-2009-0437: The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows…
PriorityP43low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.27%
19.6th percentile
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs
bugzilla·2009-04-17·CVSS 4.3
CVE-2009-1312 [MEDIUM] CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs
CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs
Mozilla community member Michael reported that when a server responds with
a Refresh header containing a javascript: URI, Firefox will redirect to the
javascript: URI. If an attacker could inject a Refresh header into a server
response, or could control the value that a site places in the Refresh
header, they could use this vulnerability to perform an XSS attack and
execute arbitrary JavaScript within the context of that site.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 2.1
Via RHSA-2009:0437 https://rhn.redhat.com/errata/RHSA-2009-0437.html
---
This issue has been addressed in following products:
Red Hat Ent
Bugzilla
CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI
bugzilla·2009-04-17·CVSS 4.3
CVE-2009-1306 [MEDIUM] CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI
CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI
Mozilla developer Daniel Veditz reported that when the jar: scheme is used
to wrap a URI which serves the content with Content-Disposition:
attachement, the HTTP header is ignored and the content is unpacked and
displayed inline. A site may depend on this HTTP header to prevent
potentially untrusted content that it serves from executing within the
context of the site. An attacker could use this vulnerability to subvert
sites using this mechanism to mitigate content injection attacks.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 2.1
Via RHSA-2009:0437 https://rhn.redhat.com/errata/RHSA-2009-0437.htm
http://www-1.ibm.com/support/docview.wss?uid=swg1PK67405http://www.securityfocus.com/bid/33849https://exchange.xforce.ibmcloud.com/vulnerabilities/48527http://www-1.ibm.com/support/docview.wss?uid=swg1PK67405http://www.securityfocus.com/bid/33849https://exchange.xforce.ibmcloud.com/vulnerabilities/48527
2009-02-10
Published