cbcvebase.
CVE-2009-0438
published 2009-02-10

CVE-2009-0438: IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information…

PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.24%
66.1th percentile
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server<= 7.0
ibmwebsphere_application_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.