CVE-2009-0891Improper Authentication in IBM Websphere Application Server

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 37.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 2

Description

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 8.0 | Impact: 4.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p5p6-vf7x-q4f7: The Web Services Security component in IBM WebSphere Application Server 72022-05-02
CVEList
CVE-2009-0891: The Web Services Security component in IBM WebSphere Application Server 72009-03-25
CVE-2009-0891 — Improper Authentication in IBM | cvebase