Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0507

Опубликовано: 26 фев. 2009
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:websphere_process_server:*:*:*:*:*:*:*:*
Версия до 6.1.2.2 (включая)
cpe:2.3:a:ibm:websphere_process_server:*:*:*:*:*:*:*:*
Версия до 6.2 (включая)
cpe:2.3:a:ibm:websphere_process_server:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_process_server:6.1.2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00267
Низкий

4 Medium

CVSS2

Дефекты

CWE-16

Связанные уязвимости

github
почти 4 года назад

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

EPSS

Процентиль: 50%
0.00267
Низкий

4 Medium

CVSS2

Дефекты

CWE-16