CVE-2009-0903: High severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0903?
CVE-2009-0903 has a moderate severity rating that allows potential exploitation by remote attackers.
How do I fix CVE-2009-0903?
To address CVE-2009-0903, upgrade to IBM WebSphere Application Server version 7.0.0.3 or later, and for version 6.1, upgrade to 6.1.0.25 or higher.
What versions of IBM WebSphere Application Server are affected by CVE-2009-0903?
CVE-2009-0903 affects IBM WebSphere Application Server versions 6.1 before 6.1.0.25 and 7.0 before 7.0.0.3.
What types of attacks can CVE-2009-0903 facilitate?
CVE-2009-0903 can facilitate unauthorized access due to improper handling of WS-Security policies on inbound requests.
Is there a workaround for CVE-2009-0903?
There are no known workarounds for CVE-2009-0903; applying the patches is the recommended mitigation.