4
CVSSv2

CVE-2009-0507

Published: 26/02/2009 Updated: 08/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

IBM WebSphere Process Server (WPS) 6.1.2 prior to 6.1.2.3 and 6.2 prior to 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere process server

ibm websphere process server 6.1.2

ibm websphere process server 6.1.2.1