| ID |
CVE-2009-0506
|
| Sažetak |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks. |
| Reference |
|
| CVSS |
| Base: | 6.2 |
| Impact: | 10.0 |
| Exploitability: | 1.9 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
HIGH |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:L/AC:H/Au:N/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
08-08-2017 - 01:33 |
| Objavljeno |
25-02-2009 - 16:30 |