CVE-2009-2091IBM Websphere Application Server vulnerability

CWE-2645 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.2%
top 54.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 2

Description

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7gx9-355f-94x4: The System Management/Repository component in IBM WebSphere Application Server (WAS) 72022-05-02
CVEList
CVE-2009-2091: The System Management/Repository component in IBM WebSphere Application Server (WAS) 72009-08-13

💬Community

1
Bugzilla
CVE-2009-5144 CVE-2015-2091 mod_gnutls: GnuTLSClientVerify require is ignored in directory and server context2015-02-27
CVE-2009-2091 — IBM vulnerability | cvebase