CVE-2009-2747

IBM WebSphere Application Server <7.0.0.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PK99480
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PK91414
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54228

Scores

EPSS 0.0193
EPSS Percentile 77.7%

Details

CWE
CWE-264
Status published
Products (50)
ibm/websphere_application_server 6.0
ibm/websphere_application_server 6.0.0.1
ibm/websphere_application_server 6.0.0.2
ibm/websphere_application_server 6.0.0.3
ibm/websphere_application_server 6.0.1
ibm/websphere_application_server 6.0.1.1
ibm/websphere_application_server 6.0.1.2
ibm/websphere_application_server 6.0.1.3
ibm/websphere_application_server 6.0.1.5
ibm/websphere_application_server 6.0.1.7
... and 40 more
Published Oct 30, 2011
Tracked Since Feb 18, 2026