CVE-2009-2743
https://notcve.org/view.php?id=CVE-2009-2743
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file. En WebSphere Application Server (WAS) de IBM versiones 6.1 anteriores a 6.1.0.27 y versiones 7.0 anteriores a 7.0.0.7, no manejan apropiadamente una excepción que se produce después del uso de scripts wsadmin y la configuración de JAAS-J2C Authentication Data, que permite a los usuarios locales obtener información confidencial mediante la lectura del archivo de registro de First Failure Data Capture (FFDC). • http://secunia.com/advisories/37796 http://www-01.ibm.com/support/docview.wss?uid=swg27007951 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK86137 http://www.vupen.com/english/advisories/2009/2721 https://exchange.xforce.ibmcloud.com/vulnerabilities/53343 •
CVE-2009-2090
https://notcve.org/view.php?id=CVE-2009-2090
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors. Vulnerabilidad no especificada en wsadmin en el componente System Management/Repository en IBM WebSphere Application Server (WAS) v7.0 anteriores a v7.0.0.5, permite a los atacantes remotos evitar las restricciones de acceso previstas para Java Management Extensions (JMX) Management Beans (aka MBeans), y causar una denegación de servicios (parada del demonio), a través de vectores desconocidos. • http://secunia.com/advisories/34461 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK86328 http://www.securityfocus.com/bid/36153 https://exchange.xforce.ibmcloud.com/vulnerabilities/52082 •
CVE-2009-2087
https://notcve.org/view.php?id=CVE-2009-2087
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors. la funcionalidad Web Services en IBM WebSphere Application Server (WAS) v6.1 anterior a v6.1.0.25 y v7.0 anterior a v7.0.0.5, en ciertas circunstancias e involucrando al archivo ibm-webservicesclient-bind.xmi y a la personalización de la encriptación de la contraseña, usa una ofuscación de contraseña débil, lo que permite a usuarios locales provocar una denegación de servicio (fallo en el despliegue) a través de vectores no especificados. • http://secunia.com/advisories/34461 http://www-01.ibm.com/support/docview.wss?uid=swg27007951 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK79275 https://exchange.xforce.ibmcloud.com/vulnerabilities/52078 • CWE-255: Credentials Management Errors •
CVE-2009-2092
https://notcve.org/view.php?id=CVE-2009-2092
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors. IBM WebSphere Application Server (WAS) v7.0 anteriores a v7.0.0.5 no lee apropiadamente el parámetro portletServingEnabled en ibm-portlet-ext.xmi, lo que permite a los atacantes remotos evitar las restricciones de acceso previstas a través de vectores desconocidos. • http://secunia.com/advisories/34461 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK89385 http://www.securityfocus.com/bid/36155 https://exchange.xforce.ibmcloud.com/vulnerabilities/52375 • CWE-284: Improper Access Control •
CVE-2009-2085
https://notcve.org/view.php?id=CVE-2009-2085
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB). El componente Security en IBM WebSphere Application Server (WAS) v6.1 anterior a v6.1.0.25 y v7.0 anterior a v7.0.0.5 no maneja adecuadamente la Aserción de Identidad (Identity Assertion) con CSIv2 Security, lo que permite a atacantes remotos evitar las restricciones de acceso establecidas con CSIv2 a través de vectores que involucran la "Enterprise JavaBeans" (EJB). • http://www-01.ibm.com/support/docview.wss?uid=swg27007951 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK83097 https://exchange.xforce.ibmcloud.com/vulnerabilities/52076 • CWE-287: Improper Authentication •