CVE-2009-2091: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Published Aug 13, 2009
·Updated
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
4 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.1
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.4
Remediation
Patch Available
Event History
Aug 13, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2091?
The severity of CVE-2009-2091 is rated as medium with a score of 5.
2
How do I fix CVE-2009-2091?
To fix CVE-2009-2091, you should apply the available patch for IBM WebSphere Application Server.
3
What type of vulnerability is CVE-2009-2091?
CVE-2009-2091 is a security vulnerability that involves weak file permissions for new applications in IBM WebSphere Application Server.
4
Can CVE-2009-2091 lead to sensitive information disclosure?
Yes, CVE-2009-2091 can allow remote attackers to obtain sensitive information due to weak file permissions.
5
Which IBM WebSphere Application Server versions are affected by CVE-2009-2091?
CVE-2009-2091 affects IBM WebSphere Application Server version 7.0 before 7.0.0.5 on z/OS.