PT-2009-3732 · Ibm · Ibm Websphere Application Server

Published

2009-03-31

·

Updated

2014-10-24

·

CVE-2009-1173

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server (WAS) versions 7.0.0 through 7.0.0.2
Description The issue is related to weak permissions used by IBM WebSphere Application Server for files associated with interim fixes. Specifically, the software uses 777 permissions instead of the intended 755 permissions, allowing attackers to modify files that should be inaccessible.
Recommendations For IBM WebSphere Application Server (WAS) versions 7.0.0 through 7.0.0.2, update to version 7.0.0.3 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1173

Affected Products

Ibm Websphere Application Server