CVE-2009-0904
IBM WebSphere Application Server 6.1 - XML Encoding Bypass via SOAP Request
Title source: llmDescription
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27007951
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK84015
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51490
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35741
Scores
EPSS
0.0202
EPSS Percentile
78.9%
Details
CWE
CWE-264
Status
published
Products (28)
ibm/websphere_application_server
6.1
ibm/websphere_application_server
6.1.0
ibm/websphere_application_server
6.1.0.1
ibm/websphere_application_server
6.1.0.2
ibm/websphere_application_server
6.1.0.3
ibm/websphere_application_server
6.1.0.4
ibm/websphere_application_server
6.1.0.5
ibm/websphere_application_server
6.1.0.6
ibm/websphere_application_server
6.1.0.7
ibm/websphere_application_server
6.1.0.8
... and 18 more
Published
Jul 05, 2009
Tracked Since
Feb 18, 2026