CVE-2009-1172 describes a critical vulnerability in the JAX-RPC WS-Security runtime of IBM WebSphere Application Server (WAS) versions 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, specifically when APAR PK41002 is installed. The flaw stems from improper validation of UsernameToken objects, leading to unknown impact and attack vectors. This vulnerability carries a CVSS score of 10.0, indicating a critical severity with network-based attack vectors, low attack complexity, and complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score is 82/100, further emphasizing its high risk. Despite its high severity, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting a lack of widespread attention or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* | ||
6.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:* | ||
6.1.0.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:* | ||
6.1.0.1CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:* | ||
6.1.0.2CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.