MEDIUM · 6.4

CVE-2009-2749

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoo...

Vulnerability Description

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmWebsphere Application Server7.0.0.7
IbmCommunications Enabled Applications<= 1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2749?

CVE-2009-2749 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoo...

How severe is CVE-2009-2749?

CVE-2009-2749 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2749?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Application Server, Ibm Communications Enabled Applications.