CVE-2009-2743

IBM WebSphere Application Server <6.1.0.27-7.0.0.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.

References (6)

Core 6
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK86137
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37796
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53343
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2721
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463

Scores

EPSS 0.0039
EPSS Percentile 31.3%

Details

Status published
Products (22)
ibm/websphere_application_server 6.1
ibm/websphere_application_server 6.1.0.1
ibm/websphere_application_server 6.1.0.2
ibm/websphere_application_server 6.1.0.3
ibm/websphere_application_server 6.1.0.5
ibm/websphere_application_server 6.1.0.7
ibm/websphere_application_server 6.1.0.9
ibm/websphere_application_server 6.1.0.11
ibm/websphere_application_server 6.1.0.13
ibm/websphere_application_server 6.1.0.15
... and 12 more
Published Sep 21, 2009
Tracked Since Feb 18, 2026