CVE-2009-1899: Critical severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1899?
CVE-2009-1899 is classified as a moderate severity vulnerability.
How do I fix CVE-2009-1899?
To resolve CVE-2009-1899, update your IBM WebSphere Application Server to the latest version that addresses this vulnerability.
Which versions of IBM WebSphere Application Server are affected by CVE-2009-1899?
CVE-2009-1899 affects IBM WebSphere Application Server versions 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5.
What type of information can be exposed due to CVE-2009-1899?
CVE-2009-1899 can potentially allow remote authenticated users to obtain sensitive information.
Is there a workaround for CVE-2009-1899 if I cannot apply the update immediately?
Currently, there are no documented workarounds for CVE-2009-1899; applying the appropriate update is recommended.