IBM WebSphere Application Server 7.0 < Fix Pack 5 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 5142

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

IBM WebSphere Application Server 7.0 before Fix Pack 5 appears to be running on the remote host. Such versions are reportedly affected by multiple vulnerabilities.

- Invoking an MBean that does not have type key-property results in a NullPointerException. (PK78743)

- Deployment fails to properly handle password in webservices client modules. (PK79275)

- IBM-portlet-ext.xmi is not reading correctly the portlet serving enable parameter. (PK89385)

- An attacker may be able to obtain sensitive information, caused by an error during the migration from WebSphere Application Server 6.1 to 7.0 when tracing is enabled. (PK80337)

- Deploying new applications on WebSphere Application Server for z/OS prior to 1.8 can result in the application being saved on the file system with insecure permissions. (PK83308)

- A security-bypass vulnerability due to a design error in the Single Sign-on with SPENEGO implementation. When setting the custom property 'ws.webcontainer.invokefilterscompatibility' to true, an attacker can bypass the SSO authentication on security URLs. (PK77465)

A security-bypass vulnerability due to an unspecified error when configured with CSIv2 Security is configured with Identity Assertion. (PK83097)

Solution

Apply Fix Pack 5 (7.0.0.5) or later.

See Also

http://www-01.ibm.com/support/docview.wss?uid=swg27014463#7005

Plugin Details

Severity: High

ID: 5142

Family: Web Servers

Published: 2009/08/27

Modified: 2016/01/15

Dependencies: 4270

Nessus ID: 40823

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:websphere_application_server

Patch Publication Date: 2009/07/27

Vulnerability Publication Date: 2009/08/26

Reference Information

CVE: CVE-2009-2085, CVE-2009-2088, CVE-2009-2089, CVE-2009-2090, CVE-2009-2091, CVE-2009-2092

BID: 36153, 36154, 36155, 36156, 36157, 36158, 36163