CVE-2009-2088: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2088?
CVE-2009-2088 is considered a high severity vulnerability due to its potential to allow remote attackers to bypass authentication.
How do I fix CVE-2009-2088?
To fix CVE-2009-2088, you should upgrade IBM WebSphere Application Server to version 6.1.0.25 or later for 6.1, and 7.0.0.5 or later for 7.0.
What are the affected versions of IBM WebSphere Application Server for CVE-2009-2088?
CVE-2009-2088 affects IBM WebSphere Application Server versions 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5.
What component is vulnerable in CVE-2009-2088?
The vulnerable component in CVE-2009-2088 is the Servlet Engine/Web Container of IBM WebSphere Application Server.
Can CVE-2009-2088 be exploited remotely?
Yes, CVE-2009-2088 can be exploited remotely, allowing attackers to bypass authentication safeguards.