CyberSec.Space Logo
Back to CVE Browser

CVE-2009-1172

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0080%
EPSS Percentile44.96th
PublishedMar 31, 2009
Last ModifiedApr 23, 2026

Vulnerability Description

The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.

Affected Platforms (CPE)

πŸ“¦
Ibm

Websphere Application Server

= 6.1
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.0
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.1
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.2
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.3
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.4
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.5
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.6
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.7
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.8
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.9
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.10
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.11
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.12
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.13
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.14
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.15
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.16
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.17
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.18
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.19
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.20
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.21
πŸ“¦
Ibm

Websphere Application Server

= 6.1.0.22
πŸ“¦
Ibm

Websphere Application Server

= 7.0
πŸ“¦
Ibm

Websphere Application Server

= 7.0.0.1

References & Advisories

Related Vulnerabilities