CVE-2009-0508: Infoleak
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0508?
CVE-2009-0508 has a CVSS score of 5.0, indicating a medium severity level.
How do I fix CVE-2009-0508?
To remediate CVE-2009-0508, upgrade IBM WebSphere Application Server to a version that is not affected, specifically to versions 6.0.2.35 or higher, 6.1.0.23 or higher, or 7.0.0.3 or higher.
What versions of IBM WebSphere Application Server are affected by CVE-2009-0508?
CVE-2009-0508 affects IBM WebSphere Application Server versions 5.1.0, 5.1.1.19, and multiple versions within the 6.x and 7.x series up to specified thresholds.
What types of attacks can exploit CVE-2009-0508?
CVE-2009-0508 can be exploited by remote attackers to read arbitrary files within WAR file directories, potentially leading to sensitive data exposure.
Is there a workaround for CVE-2009-0508?
While the best practice is to apply the necessary updates, you can limit exposure by restricting access to sensitive directories in your WebSphere configuration.