Vulnerability Description
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Application Server | 5.1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/34283Vendor Advisory
- http://secunia.com/advisories/34876Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg24022456PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK81387
- http://www-01.ibm.com/support/docview.wss?uid=swg21380233Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21380376PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27006876Patch
- http://www.securityfocus.com/bid/34104
- http://www.vupen.com/english/advisories/2009/0704PatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1188PatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1464PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49085
- http://secunia.com/advisories/34283Vendor Advisory
- http://secunia.com/advisories/34876Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg24022456PatchVendor Advisory
FAQ
What is CVE-2009-0508?
CVE-2009-0508 is a vulnerability with a CVSS score of 7.5 (HIGH). The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers...
How severe is CVE-2009-0508?
CVE-2009-0508 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0508?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Application Server.