CVE-2009-2747IBM Websphere Application Server vulnerability

CWE-2643 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.2%
top 56.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30
Latest updateMay 2

Description

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-xh6m-92pm-858v: The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 62022-05-02
CVEList
CVE-2009-2747: The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 62011-10-30
CVE-2009-2747 — IBM vulnerability | cvebase