CVE-2009-1172

critical

Description

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.

References

http://www.securityfocus.com/bid/34502

http://www-01.ibm.com/support/docview.wss?uid=swg27014463

http://www-01.ibm.com/support/docview.wss?uid=swg27007951

http://www-01.ibm.com/support/docview.wss?uid=swg21367223

http://www-01.ibm.com/support/docview.wss?uid=swg1PK75992

http://secunia.com/advisories/34461

http://secunia.com/advisories/34131

Details

Source: Mitre, NVD

Published: 2009-03-31

Updated: 2014-10-24

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical