« Volver al listado

CVE-2009-0900

Estado: ModificadaMedia (4.1)—

Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0900",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 2.7,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-10-30T19:55:00.773",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg1IC59375",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51038",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg1IC59375",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51038",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en memoria dinámica en el cliente de IBM WebSphere MQ v6.0 anterior a v6.0.2.7 y v7.0 anterior a v7.0.1.0 permite a usuarios locales conseguir privilegios a través de la información elaborada SSL en un fichero Client Channel Definition Table (CCDT)."
    }
  ],
  "lastModified": "2026-06-16T23:06:03.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6D2279B-482A-4CA6-9EF2-C57A95969BC2"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F36C644-664C-4758-9762-E808C80AE904"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C670A3F-7BBB-4115-A037-B5E732ABB6BA"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24CD8F97-39E0-455C-92CA-F0FE9AE5A0CC"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C97EC1D0-CA59-4E2C-84EB-054BF27D1BCF"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CCD33A5-6567-43CB-909D-D1851ACF4AA8"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3664585-D0B4-467C-9B6D-4F8E239F7DCD"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2216808-BAE9-4034-9618-5EC4CCB80E7F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6263B9D-A62A-4E41-958A-968F9ACA0CE6"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19983CDF-4769-4B56-98ED-CE7EE0C1AFF6"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:6.0.2.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFF09F4C-9F56-4931-8839-044491B5FA40"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "594287A4-AF30-4872-A5B8-1421FAB5C674"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:7.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "896273C9-11F9-45A0-BA46-66F37DFACCC7"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_mq:7.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF396289-8409-4FE2-96DB-99818D5680B4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}