Unrated severityNVD Advisory· Published Feb 25, 2009· Updated Jun 16, 2026
CVE-2009-0506
CVE-2009-0506
Description
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.
Affected products
14cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.20:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.22:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.24:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:*
- (no CPE)range: <6.0.2.33
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.