CVE-2009-0438: Medium severity IBM WebSphere Application Server vulnerability
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which deployments are exposed?
IBM WebSphere Application Server deployments on Windows running version 7 before 7.0.0.1 are identified as affected. The issue is remotely reachable and requires no authentication.
What does an attacker need to exploit this?
An attacker can send a crafted request to bypass Authorization checking and obtain sensitive information from JSP pages. The provided data does not indicate that any specific non-default configuration is required.
What should teams do if they identify an affected server?
Apply the available patch for the affected WebSphere Application Server version. No alternative mitigation is provided in the available data.