First published: Tue Feb 10 2009(Updated: )
The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =6.1 | |
IBM WebSphere Application Server | =6.0.2.1 | |
IBM WebSphere Application Server | =6.0.2.5 | |
IBM WebSphere Application Server | =6.0.0.3 | |
IBM WebSphere Application Server | =6.1.0.2 | |
IBM WebSphere Application Server | =6.0.1.15 | |
IBM WebSphere Application Server | =6.1.0.4 | |
IBM WebSphere Application Server | =6.0.1.3 | |
IBM WebSphere Application Server | =6.0.2.13 | |
IBM WebSphere Application Server | =6.1.0.11 | |
IBM WebSphere Application Server | =6.0.2.9 | |
IBM WebSphere Application Server | =6.0.1.11 | |
IBM WebSphere Application Server | =6.0.2.28 | |
IBM WebSphere Application Server | =6.1.0.14 | |
IBM WebSphere Application Server | =6.0.2.11 | |
IBM WebSphere Application Server | =6.0.2.6 | |
IBM WebSphere Application Server | =6.0.2.2 | |
IBM WebSphere Application Server | =6.0.2 | |
IBM WebSphere Application Server | =6.0.2.24 | |
IBM WebSphere Application Server | =6.0.1.9 | |
IBM WebSphere Application Server | =6.0.1.17 | |
IBM WebSphere Application Server | =6.0.2.15 | |
IBM WebSphere Application Server | =6.0.2.4 | |
IBM WebSphere Application Server | =6.0.2.17 | |
IBM WebSphere Application Server | =6.1.0.9 | |
IBM WebSphere Application Server | =6.0.1.2 | |
IBM WebSphere Application Server | =6.0.0.1 | |
IBM WebSphere Application Server | =6.0.2.30 | |
IBM WebSphere Application Server | =6.1.0.0 | |
IBM WebSphere Application Server | =6.1.0.1 | |
IBM WebSphere Application Server | =6.0.2.29 | |
IBM WebSphere Application Server | =6.0.2.23 | |
IBM WebSphere Application Server | =6.1.13 | |
IBM WebSphere Application Server | =6.0.1 | |
IBM WebSphere Application Server | =6.0.2.7 | |
IBM WebSphere Application Server | =6.0.0.2 | |
IBM WebSphere Application Server | =6.1.0.7 | |
IBM WebSphere Application Server | =6.0.2.27 | |
IBM WebSphere Application Server | =6.1.0.3 | |
IBM WebSphere Application Server | =6.1.0.17 | |
IBM WebSphere Application Server | =6.1.0.13 | |
IBM WebSphere Application Server | =6.1.0.16 | |
IBM WebSphere Application Server | =6.1.0.6 | |
IBM WebSphere Application Server | =6.0.2.22 | |
IBM WebSphere Application Server | =6.0.1.5 | |
IBM WebSphere Application Server | =6.1.0.10 | |
IBM WebSphere Application Server | =6.0.1.7 | |
IBM WebSphere Application Server | =6.0 | |
IBM WebSphere Application Server | =6.1.0.8 | |
IBM WebSphere Application Server | =6.1.0.15 | |
IBM WebSphere Application Server | =6.0.2.3 | |
IBM WebSphere Application Server | =6.1.0.18 | |
IBM WebSphere Application Server | =6.0.2.19 | |
IBM WebSphere Application Server | =6.0.1.1 | |
IBM WebSphere Application Server | =6.0.2.25 | |
IBM WebSphere Application Server | =6.1.0 | |
IBM WebSphere Application Server | =6.1.0.5 | |
IBM WebSphere Application Server | =6.0.1.13 | |
IBM WebSphere Application Server | =6.1.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0436 is categorized with unknown severity due to its unspecified impact and potential local attack vectors.
To mitigate CVE-2009-0436, update your IBM HTTP Server to versions 6.0.2.31 or later for 6.0.x, and 6.1.0.19 or later for 6.1.x.
CVE-2009-0436 affects IBM WebSphere Application Server versions 6.0.x prior to 6.0.2.31 and 6.1.x prior to 6.1.0.19.
CVE-2009-0436 involves vulnerabilities in the mod_ibm_ssl and mod_cgid modules of the IBM HTTP Server.
Using affected versions of IBM WebSphere Application Server without addressing CVE-2009-0436 presents potential security risks due to incorrect permissions for AF_UNIX sockets.