CVE-2009-0904

IBM WebSphere Application Server 6.1 - XML Encoding Bypass via SOAP Request

Title source: llm
STIX 2.1

Description

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27007951
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK84015
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51490
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35741

Scores

EPSS 0.0202
EPSS Percentile 78.9%

Details

CWE
CWE-264
Status published
Products (28)
ibm/websphere_application_server 6.1
ibm/websphere_application_server 6.1.0
ibm/websphere_application_server 6.1.0.1
ibm/websphere_application_server 6.1.0.2
ibm/websphere_application_server 6.1.0.3
ibm/websphere_application_server 6.1.0.4
ibm/websphere_application_server 6.1.0.5
ibm/websphere_application_server 6.1.0.6
ibm/websphere_application_server 6.1.0.7
ibm/websphere_application_server 6.1.0.8
... and 18 more
Published Jul 05, 2009
Tracked Since Feb 18, 2026