VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0217 to the following vulnerability:
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217 http://www.w3.org/QA/2009/07/hmactruncationinxmlsignatu.html http://www.kb.cert.org/vuls/id/466161 http://secunia.com/advisories/35855/2/ https://issues.apache.org/bugzilla/showbug.cgi?id=47526 http://www.w3.org/2008/06/xmldsigcore-errata.html#e03 http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html
References from US-CERT's VU#466161: ------------------------------------- http://www.w3.org/2008/06/xmldsigcore-errata.html#e03 http://www.w3.org/QA/2009/07/hmactruncationinxmlsignatu.html http://www.rsa.com/blog/blogentry.aspx?id=1492 http://www.w3.org/TR/xmldsig-core/ http://www.w3.org/TR/xmldsig-core/#sec-HMAC http://tools.ietf.org/html/rfc2104#section-5 http://www.oasis-open.org/specs/index.php#wss http://www.w3.org/2000/xp/Group/ http://msdn.microsoft.com/en-us/library/ms996502.aspx http://www.ibm.com/support/docview.wss?rs=180&uid=swg21384925 http://santuario.apache.org/download.html http://www.mono-project.com/Vulnerabilities http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html http://www.aleksey.com/xmlsec/downloads.html
Credit: ------- Thomas Roessler of the W3C
The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.