CVE-2009-0904: Medium severity ibm websphere application server feature pack for web services vulnerability
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0904?
CVE-2009-0904 is classified as a high-severity vulnerability due to its potential to allow unauthorized access and data modification.
How do I fix CVE-2009-0904?
To resolve CVE-2009-0904, upgrade your IBM WebSphere Application Server to version 6.1.0.25 or later.
What does CVE-2009-0904 affect?
CVE-2009-0904 affects various versions of IBM WebSphere Application Server 6.1 prior to 6.1.0.25.
Can CVE-2009-0904 be exploited remotely?
Yes, CVE-2009-0904 can be exploited remotely, allowing attackers to bypass access restrictions.
What type of attack does CVE-2009-0904 enable?
CVE-2009-0904 enables XML fuzzing attacks via compromised SOAP requests.