CVE-2009-1173

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:01

Type Values Removed Values Added
References () http://secunia.com/advisories/34131 - () http://secunia.com/advisories/34131 -
References () http://secunia.com/advisories/34461 - Vendor Advisory () http://secunia.com/advisories/34461 - Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg27014463 - Patch () http://www-01.ibm.com/support/docview.wss?uid=swg27014463 - Patch
References () http://www.securityfocus.com/bid/34259 - () http://www.securityfocus.com/bid/34259 -
References () http://www.vupen.com/english/advisories/2009/0854 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/0854 - Patch, Vendor Advisory

Information

Published : 2009-03-31 14:09

Updated : 2024-11-21 01:01


NVD link : CVE-2009-1173

Mitre link : CVE-2009-1173

CVE.ORG link : CVE-2009-1173


JSON object : View

Products Affected

ibm

  • websphere_application_server
CWE
CWE-264

Permissions, Privileges, and Access Controls