CVE-2009-0892: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0892?
CVE-2009-0892 is classified as a medium severity vulnerability due to its potential for session hijacking under specific scenarios.
How do I fix CVE-2009-0892?
To address CVE-2009-0892, upgrade your IBM WebSphere Application Server to version 6.1.0.23 or 7.0.0.3 or later.
Which versions of IBM WebSphere Application Server are affected by CVE-2009-0892?
CVE-2009-0892 affects IBM WebSphere Application Server versions 6.1 prior to 6.1.0.23 and version 7.0 prior to 7.0.0.3.
What type of attack does CVE-2009-0892 enable?
CVE-2009-0892 enables session hijacking attacks, allowing unauthorized users to gain access to the administrative console.
What is the impact of exploiting CVE-2009-0892?
Exploitation of CVE-2009-0892 can lead to unauthorized access and control of user sessions in the IBM WebSphere Application Server administrative console.