7.5
CVSSv2

CVE-2009-0903

Published: 25/06/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

IBM WebSphere Application Server (WAS) 7.0 prior to 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 prior to 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote malicious users to bypass intended access restrictions via a crafted request to a JAX-WS application.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 6.1.0.4

ibm websphere application server 6.1.0.21

ibm websphere application server 6.1.0.3

ibm websphere application server 6.1.0.10

ibm websphere application server 6.1.0.0

ibm websphere application server 6.1.0

ibm websphere application server 7.0.0.1

ibm websphere application server 6.1.0.8

ibm websphere application server 6.1.0.6

ibm websphere application server 6.1.0.1

ibm websphere application server 6.1.0.16

ibm websphere application server 6.1.0.2

ibm websphere application server 6.1.0.14

ibm websphere application server 6.1.0.17

ibm websphere application server 6.1.0.18

ibm websphere application server 7.0

ibm websphere application server 6.1.0.20

ibm websphere application server 6.1.0.22

ibm websphere application server 6.1.0.5

ibm websphere application server 6.1.0.15

ibm websphere application server 6.1.0.9

ibm websphere application server 6.1.0.11

ibm websphere application server 6.1.0.19

ibm websphere application server 6.1.0.24

ibm websphere application server 6.1.0.23

ibm websphere application server 6.1.0.7

ibm websphere application server 6.1.0.13

ibm websphere application server 6.1.0.12

ibm websphere application server 6.1