CVE Database
/

CVE-2009-1172

Back to search

CVE-2009-1172

Published: Mar 31, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

34131
third-party-advisory
x_refsource_SECUNIA
34461
third-party-advisory
x_refsource_SECUNIA
PK75992
vendor-advisory
x_refsource_AIXAPAR
34502
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now