CVE-2009-2749: Medium severity ibm websphere application server feature pack for web services vulnerability
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2749?
CVE-2009-2749 has been classified as a medium severity vulnerability due to the potential for session spoofing.
How do I fix CVE-2009-2749?
To mitigate CVE-2009-2749, upgrade IBM WebSphere Application Server and Communications Enabled Applications to versions that patch the predictable session value issue.
What type of attacks can exploit CVE-2009-2749?
CVE-2009-2749 can be exploited by man-in-the-middle attackers to spoof collaboration sessions.
Which IBM products are affected by CVE-2009-2749?
CVE-2009-2749 affects IBM WebSphere Application Server version 7.0.0.7 and earlier versions of Communications Enabled Applications.
What are the potential consequences of CVE-2009-2749 being exploited?
Exploitation of CVE-2009-2749 can lead to unauthorized access to collaboration sessions, compromising user data and session integrity.