CVE-2009-2093
IBM WebSphere Partner Gateway 6.0-6.2 - Authenticated SQL Injection
Title source: llmDescription
SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
References (9)
Core 9
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2292
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR32609
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR32608
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR32386
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52393
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR32607
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21382117
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36295
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR33176
Scores
EPSS
0.0128
EPSS Percentile
67.0%
Details
CWE
CWE-89
Status
published
Products (4)
ibm/websphere_partner_gateway
6.0.0 (2 CPE variants)
ibm/websphere_partner_gateway
6.1.0 (2 CPE variants)
ibm/websphere_partner_gateway
6.1.1 (3 CPE variants)
ibm/websphere_partner_gateway
6.2 (2 CPE variants)
Published
Aug 13, 2009
Tracked Since
Feb 18, 2026