{"api_version":"1","generated_at":"2026-07-23T13:57:31+00:00","cve":"CVE-2009-1173","urls":{"html":"https://cve.report/CVE-2009-1173","api":"https://cve.report/api/cve/CVE-2009-1173.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1173","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1173"},"summary":{"title":"CVE-2009-1173","description":"IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified \"interim fixes,\" which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-31 14:09:53","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/34461","name":"http://secunia.com/advisories/34461","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM WebSphere Application Server Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34131","name":"http://secunia.com/advisories/34131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM PK82988: SHIP APAR FIXES FOR H28W700 FIX PACK 7.0.0.3.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2009/0854","name":"http://www.vupen.com/english/advisories/2009/0854","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463","name":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"IBM Fix list for IBM WebSphere Application Server V7.0 - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34259","name":"http://www.securityfocus.com/bid/34259","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1173","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1173","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1173","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1173","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:04:48.432Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2009-0854","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0854"},{"name":"34259","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34259"},{"name":"34131","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34131"},{"name":"34461","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34461"},{"name":"PK77590","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463"},{"name":"PK82988","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified \"interim fixes,\" which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-10-20T13:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2009-0854","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0854"},{"name":"34259","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34259"},{"name":"34131","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34131"},{"name":"34461","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34461"},{"name":"PK77590","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463"},{"name":"PK82988","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1173","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified \"interim fixes,\" which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2009-0854","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0854"},{"name":"34259","refsource":"BID","url":"http://www.securityfocus.com/bid/34259"},{"name":"34131","refsource":"SECUNIA","url":"http://secunia.com/advisories/34131"},{"name":"34461","refsource":"SECUNIA","url":"http://secunia.com/advisories/34461"},{"name":"PK77590","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK77590"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg27014463"},{"name":"PK82988","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1173","datePublished":"2009-03-31T10:00:00.000Z","dateReserved":"2009-03-30T00:00:00.000Z","dateUpdated":"2024-08-07T05:04:48.432Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-31 14:09:53","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"B0905C80-A1BA-49CD-90CA-9270ECC3940C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"B108457A-50DC-4432-9E30-98ADBEBF2389"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1173","Ordinal":"1","Title":"CVE-2009-1173","CVE":"CVE-2009-1173","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1173","Ordinal":"1","NoteData":"IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified \"interim fixes,\" which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.","Type":"Description","Title":"CVE-2009-1173"},{"CveYear":"2009","CveId":"1173","Ordinal":"2","NoteData":"2009-03-31","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1173","Ordinal":"3","NoteData":"2014-10-20","Type":"Other","Title":"Modified"}]}}}