IBM WebSphere Application Server 6.1 < Fix Pack 21 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 4929


The remote host is vulnerable to multiple attack vectors.


IBM WebSphere Application Server 6.1 before Fix Pack 21 appears to be running on the remote host. Such versions are reportedly affected by multiple flaws :

- Provided Performance Monitoring Infrastructure (PMI) is
enabled. It may be possible for a local attacker to
obtain sensitive information through 'Systemout.log' and
'ffdc' files which are written by PerfServlet.
- SSL Configuration settings attribute 'Security Level'
does not correctly enforce the level of encryption used
by the application server. (PK63182)


Apply Fix Pack 21 ( or higher.

See Also;uid=swg1PK63182

Plugin Details

Severity: Medium

ID: 4929

Family: Web Servers

Published: 2009/02/12

Modified: 2016/01/21

Dependencies: 4270

Nessus ID: 35659

Risk Information

Risk Factor: Medium


Base Score: 5.1

Temporal Score: 5

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 5.6

Temporal Score: 4.9


Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:websphere_application_server

Reference Information

CVE: CVE-2008-4283, CVE-2008-4284, CVE-2009-0432, CVE-2009-0433, CVE-2009-0435, CVE-2009-0436, CVE-2009-0438, CVE-2009-0434

BID: 33700