CVE-2009-0507 Information
Feb 14, 2021
cve
Description
IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console which allows remote authenticated users to obtain the (1) JMSAPI (2) ESCALATION and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.
Reference
http://secunia.com/advisories/34249 http://www.vupen.com/english/advisories/2009/0670 http://www-01.ibm.com/support/docview.wss?uid=swg27015580 http://www-1.ibm.com/support/docview.wss?uid=swg1JR30088 https://exchange.xforce.ibmcloud.com/vulnerabilities/48892
Share on: