cbcvebase.
CVE-2009-0504
published 2009-02-17

CVE-2009-0504: WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed…

PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.3th percentile
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

Affected

1 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server<= 7.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.