CVE Database
/

CVE-2009-0891

Back to search

CVE-2009-0891

Published: Mar 25, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.

VendorProductVersions

n/a

n/a

affected
n/a

References

34131
third-party-advisory
x_refsource_SECUNIA
PK66676
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2009-0891 - Security Vulnerability | QwikSec