CVE-2009-1898
Status: ModifiedMedium (5)—
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.44%
- Percentile among all scored CVEs: 72
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://secunia.com/advisories/35301
- http://www-01.ibm.com/support/docview.wss?uid=swg27006876
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010
- http://www.securityfocus.com/bid/35405
- http://www.vupen.com/english/advisories/2009/1464
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51170
- http://secunia.com/advisories/35301
- http://www-01.ibm.com/support/docview.wss?uid=swg27006876
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010
- http://www.securityfocus.com/bid/35405
- http://www.vupen.com/english/advisories/2009/1464
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51170
Raw JSON (NVD)
Show
{
"id": "CVE-2009-1898",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-06-03T17:00:00.610",
"references": [
{
"url": "http://secunia.com/advisories/35301",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27006876",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/35405",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/1464",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51170",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/35301",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg27006876",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/35405",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2009/1464",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51170",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network."
},
{
"lang": "es",
"value": "la página de \"secure login\" en el componente Administrative console en IBM WebSphere Application Server (WAS)v6.0.2 anterior a v6.0.2.35 no redirecciona a una página https hasta que recibe una petición http, lo que facilita a atacantes remotos la lectura de los contenidos de las sesiones WAS capturando paquetes de la red."
}
],
"lastModified": "2026-06-16T23:08:18.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37136805-596C-4FE4-896C-15FFF1E109D8",
"versionEndIncluding": "6.0.2.33"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "714C405D-1E8F-45C1-8A09-5103F0080C76"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7F31FD3-8681-4F07-9644-5CC87D512520"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2604E01-E43E-4882-8896-5E646E850286"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "458BAD79-958E-4665-B1F8-0D46E0C57045"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B68EE27-CC4F-4530-9DFE-D94171C45F64"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC1A723F-D685-4FE5-8938-5682A2D02155"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "810E5AEC-5C35-4962-B9BB-32D66290D1D2"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9643B593-DADF-4F57-B41E-541C7F554A4C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CEBF289-F630-4386-8F79-5A1BF73BE6F6"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "521DB050-3C94-49BF-8666-6EC2C358AA27"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A98E5593-1534-48E2-8CD5-B2D1CACDDAB8"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB4AB6BD-4439-4100-A3CE-4600AED10B65"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD71D5EA-9AF5-422C-810A-D136A5F132F6"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "375DF4AF-3C7C-47C3-BBB8-AF2B3827AC13"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C9D6BDA-39E1-4D15-9D86-E212809998FB"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91CC2DA7-BAA6-4061-8D0C-81F002DEF06D"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F2A78FE-8FA6-4532-9E9E-CF6F860EFAE9"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59BEDD70-B6DB-448F-A998-3E8774B0DB8C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63099EF9-0512-44CD-946A-9B25144E50D9"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F200042C-D45E-4CAD-BF6E-E3DADF4D1D21"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9132BB1-5E2E-4CA6-9B63-027CF2A7229D"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D839EDB9-A44F-4F7F-94EF-1A77371D705C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4421929D-C4B9-43C5-BE61-E68484D3B198"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.23:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB622117-C91F-47D2-9832-B7DB340796E8"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.24:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D65E0CC-FA8C-41FD-B256-47DB0C9757FC"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.25:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D87691D-0719-4447-B258-5FA2BD10F11A"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5827DEC-ED8A-48D9-8C27-3B49D720E7B4"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D0B1A00-191D-49B2-8841-FB6C48A5D0C2"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF771E28-65AC-4A94-8A51-4EA77BC3D0B3"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5594891-E790-44E7-BC9E-0A413B385E1B"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C286007A-361F-47BB-A099-E041D5CF6E48"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:6.0.2.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD464F13-942D-40EC-8144-6D23A0AEAA81"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}