CVE Database
/

CVE-2009-0507

Back to search

CVE-2009-0507

Published: Feb 26, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2009-0670
vdb-entry
x_refsource_VUPEN
JR30088
vendor-advisory
x_refsource_AIXAPAR
34249
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now