{"api_version":"1","generated_at":"2026-07-23T11:31:53+00:00","cve":"CVE-2009-0897","urls":{"html":"https://cve.report/CVE-2009-0897","api":"https://cve.report/api/cve/CVE-2009-0897.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0897","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0897"},"summary":{"title":"CVE-2009-0897","description":"IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the \"schema DB2 instance id\" and the bcgarchive (aka the archiver script).","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-21 15:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/35136","name":"http://www.securityfocus.com/bid/35136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Partner Gateway 'bcgarchive' Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50643","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50643","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21366016","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21366016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM - WPG Instance ID required for executing archiver script","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0897","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0897","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_partner_gateway","cpe6":"6.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_partner_gateway","cpe6":"6.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:48:52.699Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JR31482","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21366016"},{"name":"35136","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35136"},{"name":"websphere-pg-bcgarchive-info-disclosure(50643)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50643"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the \"schema DB2 instance id\" and the bcgarchive (aka the archiver script)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"JR31482","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21366016"},{"name":"35136","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35136"},{"name":"websphere-pg-bcgarchive-info-disclosure(50643)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50643"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0897","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the \"schema DB2 instance id\" and the bcgarchive (aka the archiver script)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"JR31482","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21366016"},{"name":"35136","refsource":"BID","url":"http://www.securityfocus.com/bid/35136"},{"name":"websphere-pg-bcgarchive-info-disclosure(50643)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50643"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0897","datePublished":"2009-05-21T15:00:00.000Z","dateReserved":"2009-03-14T00:00:00.000Z","dateUpdated":"2024-08-07T04:48:52.699Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-21 15:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_partner_gateway:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"69E55335-9BDD-451B-A610-9389F072279D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_partner_gateway:6.1.1:*:*:*:*:*:*:*","matchCriteriaId":"BC33F02F-2381-4A6F-B322-B22E416B6887"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"897","Ordinal":"1","Title":"CVE-2009-0897","CVE":"CVE-2009-0897","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"897","Ordinal":"1","NoteData":"IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the \"schema DB2 instance id\" and the bcgarchive (aka the archiver script).","Type":"Description","Title":"CVE-2009-0897"},{"CveYear":"2009","CveId":"897","Ordinal":"2","NoteData":"2009-05-21","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"897","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}