CVE-2009-0903IBM Websphere Application Server vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 39.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 2

Description

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f83x-qcw9-92pv: IBM WebSphere Application Server (WAS) 72022-05-02
CVEList
CVE-2009-0903: IBM WebSphere Application Server (WAS) 72009-06-24
CVE-2009-0903 — IBM vulnerability | cvebase