PT-2009-3160 · Ibm · Ibm Websphere Process Server

Published

2009-02-26

·

Updated

2017-08-08

·

CVE-2009-0507

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Process Server (WPS) versions 6.1.2 through 6.1.2.2 IBM WebSphere Process Server (WPS) versions 6.2 through 6.2.0.0
Description The issue allows remote authenticated users to obtain cleartext passwords, including JMSAPI, ESCALATION, and MAILSESSION (also known as mail session), by accessing a cluster member. This occurs because configuration data is not properly restricted during the export of the cluster configuration file from the administrative console.
Recommendations For IBM WebSphere Process Server (WPS) versions 6.1.2 through 6.1.2.2, update to version 6.1.2.3 or later. For IBM WebSphere Process Server (WPS) versions 6.2 through 6.2.0.0, update to version 6.2.0.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0507

Affected Products

Ibm Websphere Process Server