PT-2009-3493 · Ibm · Ibm Websphere Application Server

Published

2009-07-05

·

Updated

2017-08-17

·

CVE-2009-0904

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 6.1 through 6.1.0.24
Description The issue is related to the improper processing of XML encoding by the IBM Stax XMLStreamWriter in the Web Services component. This allows remote attackers to bypass intended access restrictions and possibly modify data via XML fuzzing attacks sent through SOAP requests.
Recommendations For IBM WebSphere Application Server versions 6.1 through 6.1.0.24, update to version 6.1.0.25 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0904

Affected Products

Ibm Websphere Application Server