Show plain JSON{"id": "CVE-2009-0506", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.2, "accessVector": "LOCAL", "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "HIGH", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "MEDIUM", "obtainAllPrivilege": true, "exploitabilityScore": 1.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2009-02-25T16:30:00.420", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27006876", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK71143", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/33884", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48886", "source": "cve@mitre.org"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27006876", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK71143", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/33884", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48886", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks."}, {"lang": "es", "value": "Vulnerabilidad sin especificar en IBM WebSphere Application Server (WAS) v5.1 y v6.0.2 anterior a v6.0.2.33 sobre z/OS, cuando est\u00e1 activado CSIv2 Identity Assertion y la interacci\u00f3n de Enterprise JavaBeans (EJB) ocurre entre una instancia de WAS v6.1 y WAS pre-6.1, permite a usuarios locales tener un impacto desconocido a trav\u00e9s de vectores relacionados con (1) un uso del sujeto err\u00f3neo y (2)m\u00faltiples comprobaciones CBIND."}], "lastModified": "2024-11-21T01:00:04.293", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66DB2053-6DFD-4FF6-A6E9-444281531E24"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "714C405D-1E8F-45C1-8A09-5103F0080C76"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B68EE27-CC4F-4530-9DFE-D94171C45F64"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "810E5AEC-5C35-4962-B9BB-32D66290D1D2"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CEBF289-F630-4386-8F79-5A1BF73BE6F6"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A98E5593-1534-48E2-8CD5-B2D1CACDDAB8"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD71D5EA-9AF5-422C-810A-D136A5F132F6"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C9D6BDA-39E1-4D15-9D86-E212809998FB"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F2A78FE-8FA6-4532-9E9E-CF6F860EFAE9"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63099EF9-0512-44CD-946A-9B25144E50D9"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9132BB1-5E2E-4CA6-9B63-027CF2A7229D"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4421929D-C4B9-43C5-BE61-E68484D3B198"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D65E0CC-FA8C-41FD-B256-47DB0C9757FC"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:ibm:z\\/os:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "28A9DB7F-187D-42BA-B271-1C302E529BFB"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org", "evaluatorSolution": "Per http://www-01.ibm.com/support/docview.wss?uid=swg27006876#60223:\r\n\r\n\"Note: WebSphere Application Server V6.0.2 Fix Pack 2 (6.0.2.2), Fix Pack 4 (6.0.2.4), Fix Pack 6 (6.0.2.6), Fix Pack 8 (6.0.2.8), Fix Pack 10 (6.0.2.10), Fix Pack 12 (6.0.2.12), Fix Pack 14 (6.0.2.14), Fix Pack 16 (6.0.2.16), Fix Pack 18 (6.0.2.18), Fix Pack 20 (6.0.2.20), Fix Pack 22 (6.0.2.22) and Fix Pack 24 (6.0.2.24) were only published for the z/OS\u00ae platform.\""}