← Back

CVE-2009-0506

nvd nist
Published: Feb 25, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.2
Vector
AV:L/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 1.9 / Impact: 10.0
Source: NVD

Description

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

Affected (13)

1 product
Websphere Application Server
Configuration A
13 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 5.1.0
Version 6.0.2.10
Version 6.0.2.12
Version 6.0.2.14
Version 6.0.2.16
Version 6.0.2.18
Version 6.0.2.20
Version 6.0.2.22
Version 6.0.2.24
Version 6.0.2.4
Version 6.0.2.6
Version 6.0.2.8
Version 6.0.2
Running on/withPlatform Versions
Ibm
Z/os
All versions

References (8)

Timeline

No history available yet.