
CVE-2009-1172
https://notcve.org/view.php?id=CVE-2009-1172
31 Mar 2009 — The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors. El JAX-RPC Runtime WS-Security en el componente Web Services Security en IBM WebSphere Application Server (WAS) v6.1 versiones anteriores a v6.1.0.23 y v7.0 versiones anteriores a v7.0.0.3, cuando APAR PK41002 está instalado, no... • http://secunia.com/advisories/34131 • CWE-20: Improper Input Validation •

CVE-2009-1173
https://notcve.org/view.php?id=CVE-2009-1173
31 Mar 2009 — IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used. IBM WebSphere Application Server (WAS) v7.0 anterior a v7.0.0.3 utiliza permisos débiles (777) para ficheros asociados con "correcciones parciales" sin especificar, lo que permite a atacantes modificar ficheros que podría no haber estado accesible si lo... • http://secunia.com/advisories/34131 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2009-1174
https://notcve.org/view.php?id=CVE-2009-1174
31 Mar 2009 — The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors. El componente Web Services Security en IBM WebSphere Application Server (WAS) v7.0 versiones anteriores a v7.0.0.3 tiene un "problema de seguridad" no especificado en la especificación firma-digital XML, lo cual tiene un impacto y vectores de ataque desconocidos... • http://secunia.com/advisories/34131 • CWE-310: Cryptographic Issues •

CVE-2009-0892
https://notcve.org/view.php?id=CVE-2009-0892
31 Mar 2009 — The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout. La consola de administración en IBM WebSphere Application Server (WAS) v6.1 versiones anteriores a v6.1.0.23 y v7.0 versiones anteriores a v7.0.0.3 permite a atacantes secuestrar sesiones de usuarios en "escenarios específicos" relacionados con cierres de sesión forzadas. • http://secunia.com/advisories/34131 • CWE-287: Improper Authentication •

CVE-2009-0508
https://notcve.org/view.php?id=CVE-2009-0508
16 Mar 2009 — The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console. El componente Servlet Engine/Web Container en IBM WebSphere Application Server (WAS) v5.1.0, v5.1.1.19, v... • http://secunia.com/advisories/34283 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •