CVE-2009-0906
Estado: ModificadaMedia (6.5)—
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://secunia.com/advisories/36306
- http://www-01.ibm.com/support/docview.wss?uid=swg27015429
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52074
- http://secunia.com/advisories/36306
- http://www-01.ibm.com/support/docview.wss?uid=swg27015429
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52074
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-0906",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-08-13T18:30:00.233",
"references": [
{
"url": "http://secunia.com/advisories/36306",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27015429",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52074",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/36306",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27015429",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52074",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors."
},
{
"lang": "es",
"value": "El Service Component Architecture (SCA) \"feature pack\" para IBM WebSphere Application Server (WAS) SCA v1.0 anterior a v1.0.0.3, permite a usuarios autenticados remotamente evitar las restricciones de acceso establecidas por authentication.transport y obtener acceso no especificado a través de vectores desconocidos."
}
],
"lastModified": "2026-06-16T23:06:04.753",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDFDC724-24B4-4FC2-9018-C915B4275790"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:1.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "538B9F5A-5160-430B-8028-940DEE765D3C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}