CVE-2009-1172: Input Validation
The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Feature Pack for Web Servicesto a version that resolves this vulnerability.Fixed in 6.1.0.23 - Upgrade
Upgrade
IBM WebSphere Application Server Feature Pack for Web Servicesto a version that resolves this vulnerability.Fixed in 7.0.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1172?
CVE-2009-1172 has an unknown severity level due to the lack of specific details on its impact.
How do I fix CVE-2009-1172?
To fix CVE-2009-1172, upgrade your IBM WebSphere Application Server to version 6.1.0.23 or higher, or to version 7.0.0.3 or higher.
Which versions of IBM WebSphere Application Server are affected by CVE-2009-1172?
CVE-2009-1172 affects IBM WebSphere Application Server versions 6.1 prior to 6.1.0.23 and version 7.0 prior to 7.0.0.3.
What component of IBM WebSphere Application Server does CVE-2009-1172 involve?
CVE-2009-1172 involves the JAX-RPC WS-Security runtime within the Web Services Security component.
Is there a known exploit for CVE-2009-1172?
As of the details provided, the specific attack vectors and exploit details for CVE-2009-1172 remain unknown.