CVE-2009-1174

IBM WebSphere Application Server 6.0.2-7.0 Security Bypass via Web Services XML Digital-Signature

Title source: llm
STIX 2.1

Description

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34506
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35301
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34131
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34461
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21384925
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1464
Not Applicable vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK80596

Scores

EPSS 0.0236
EPSS Percentile 82.0%

Details

CWE
CWE-310
Status published
Products (2)
ibm/websphere_application_server 7.0
ibm/websphere_application_server 7.0.0.1
Published Mar 31, 2009
Tracked Since Feb 18, 2026