CVE-2009-0899: Medium severity IBM Integrated Solutions Console vulnerability
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0899?
CVE-2009-0899 has been rated as a moderate severity vulnerability.
How do I fix CVE-2009-0899?
To fix CVE-2009-0899, upgrade to the latest version of the affected IBM software that addresses this vulnerability.
What software versions are affected by CVE-2009-0899?
CVE-2009-0899 affects IBM WebSphere Application Server versions 6.1 to 6.1.0.24 and 7.0 to 7.0.0.4, IBM WebSphere Portal Server versions 5.1 to 6.0, and IBM Integrated Solutions Console version 6.0.1.
What is the impact of CVE-2009-0899?
The impact of CVE-2009-0899 can potentially allow unauthorized access due to misconfiguration of the security settings.
Who is responsible for addressing CVE-2009-0899?
It is the responsibility of organizations using the affected IBM products to ensure they apply necessary updates to mitigate CVE-2009-0899.