ID |
CVE-2009-0506
|
Sažetak |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks. |
Reference |
|
CVSS |
Base: | 6.2 |
Impact: | 10.0 |
Exploitability: | 1.9 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
HIGH |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
COMPLETE |
COMPLETE |
COMPLETE |
|
CVSS vektor |
AV:L/AC:H/Au:N/C:C/I:C/A:C |
Zadnje važnije ažuriranje |
08-08-2017 - 01:33 |
Objavljeno |
25-02-2009 - 16:30 |