{"api_version":"1","generated_at":"2026-07-23T10:58:43+00:00","cve":"CVE-2009-0906","urls":{"html":"https://cve.report/CVE-2009-0906","api":"https://cve.report/api/cve/CVE-2009-0906.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0906","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0906"},"summary":{"title":"CVE-2009-0906","description":"The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-08-13 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429","name":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Fix list for SCA Feature Pack for WebSphere Application Server V7.0","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36306","name":"http://secunia.com/advisories/36306","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM WebSphere Application Server Feature Pack for SCA Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52074","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52074","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0906","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0906","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"906","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"906","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"1.0.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:57:16.322Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"was-sca-scaallauthorizedusers-sec-bypass(52074)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52074"},{"name":"PK86047","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047"},{"name":"36306","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36306"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-07-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"was-sca-scaallauthorizedusers-sec-bypass(52074)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52074"},{"name":"PK86047","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047"},{"name":"36306","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36306"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0906","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"was-sca-scaallauthorizedusers-sec-bypass(52074)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52074"},{"name":"PK86047","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK86047"},{"name":"36306","refsource":"SECUNIA","url":"http://secunia.com/advisories/36306"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg27015429"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0906","datePublished":"2009-08-13T18:00:00.000Z","dateReserved":"2009-03-14T00:00:00.000Z","dateUpdated":"2024-08-07T04:57:16.322Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-08-13 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:1.0:*:*:*:*:*:*:*","matchCriteriaId":"BDFDC724-24B4-4FC2-9018-C915B4275790"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:1.0.0.2:*:*:*:*:*:*:*","matchCriteriaId":"538B9F5A-5160-430B-8028-940DEE765D3C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"906","Ordinal":"1","Title":"CVE-2009-0906","CVE":"CVE-2009-0906","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"906","Ordinal":"1","NoteData":"The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.","Type":"Description","Title":"CVE-2009-0906"},{"CveYear":"2009","CveId":"906","Ordinal":"2","NoteData":"2009-08-13","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"906","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}