Description
IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35228
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35347
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1512
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21389281
Scores
EPSS
0.0095
EPSS Percentile
57.4%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/filenet_content_manager
4.0
ibm/filenet_content_manager
4.0.1
ibm/filenet_content_manager
4.5
Published
Jun 08, 2009
Tracked Since
Feb 18, 2026