CVE-2009-2085

IBM WebSphere Application Server <6.1.0.25-7.0.0.5 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52076
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK83097

Scores

EPSS 0.0237
EPSS Percentile 81.7%

Details

CWE
CWE-287
Status published
Products (31)
ibm/websphere_application_server 6.1
ibm/websphere_application_server 6.1.0
ibm/websphere_application_server 6.1.0.0
ibm/websphere_application_server 6.1.0.1
ibm/websphere_application_server 6.1.0.2
ibm/websphere_application_server 6.1.0.3
ibm/websphere_application_server 6.1.0.4
ibm/websphere_application_server 6.1.0.5
ibm/websphere_application_server 6.1.0.6
ibm/websphere_application_server 6.1.0.7
... and 21 more
Published Aug 13, 2009
Tracked Since Feb 18, 2026