CVE-2009-0503: Low severity IBM WebSphere Message Broker vulnerability
Published Feb 13, 2009
·Updated
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.
Affected Software
2 affected components
IBM WebSphere Message Broker<=6.1.0.1
IBM WebSphere Message Broker=6.1
Remediation
Event History
Feb 13, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0503?
CVE-2009-0503 is classified as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2009-0503?
To mitigate CVE-2009-0503, upgrade IBM WebSphere Message Broker to version 6.1.0.2 or later.
3
What type of information is exposed in CVE-2009-0503?
CVE-2009-0503 exposes database connection passwords in the Event Log and System Log.
4
Who is affected by CVE-2009-0503?
CVE-2009-0503 affects local users of IBM WebSphere Message Broker versions 6.1.x prior to 6.1.0.2.
5
What are the potential impacts of CVE-2009-0503?
The potential impacts of CVE-2009-0503 include unauthorized access to sensitive database credentials by local users.