CVE-2009-1174Improper Check for Unusual or Exceptional Conditions in IBM Websphere Application Server

Severity
10.0CRITICALNVD
EPSS
1.2%
top 21.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateDec 30

Description

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Linuxlinux/linux_kernel5.7.06.0.19+1

Patches

🔴Vulnerability Details

3
OSV
vhost_vdpa: fix the crash in unmap a large memory2025-12-30
GHSA
GHSA-f454-gp59-g2j5: The Web Services Security component in IBM WebSphere Application Server (WAS) 62022-05-02
CVEList
CVE-2009-1174: The Web Services Security component in IBM WebSphere Application Server (WAS) 62009-03-31

📋Vendor Advisories

1
Red Hat
kernel: Linux kernel (vhost_vdpa): Denial of service via large memory unmap2025-12-30
CVE-2009-1174 — IBM vulnerability | cvebase