CVE-2009-0507 Information

Description

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console which allows remote authenticated users to obtain the (1) JMSAPI (2) ESCALATION and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

Reference

http://secunia.com/advisories/34249 http://www.vupen.com/english/advisories/2009/0670 http://www-01.ibm.com/support/docview.wss?uid=swg27015580 http://www-1.ibm.com/support/docview.wss?uid=swg1JR30088 https://exchange.xforce.ibmcloud.com/vulnerabilities/48892

Share on: