CVE-2009-0432: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server (WAS)to a version that resolves this vulnerability.Fixed in 6.1.0.19
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0432?
CVE-2009-0432 is considered to have a medium severity level due to its potential to expose sensitive information to remote attackers.
How do I fix CVE-2009-0432?
To fix CVE-2009-0432, you should upgrade your IBM WebSphere Application Server to version 6.1.0.19 or later.
What versions of IBM WebSphere Application Server are affected by CVE-2009-0432?
CVE-2009-0432 affects IBM WebSphere Application Server versions 6.1.0.1 through 6.1.0.17.
What type of vulnerability is CVE-2009-0432?
CVE-2009-0432 is a security vulnerability that allows remote attackers to obtain sensitive information due to improper configuration.
Can the risk of CVE-2009-0432 be mitigated?
Mitigation of CVE-2009-0432 can be achieved by ensuring that the secure version of the File Transfer servlet is enabled and by updating to the patched version.