Vulnerability Name: | CVE-2013-5426 (CCN-87535) | ||||||||
Assigned: | 2013-12-16 | ||||||||
Published: | 2013-12-16 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. | ||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:P) 3.6 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5426 Source: CCN Type: SA56163 IBM InfoSphere Master Data Management Session Fixation Vulnerability Source: CCN Type: IBM Security Bulletin 1660082 Session Fixation Vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition (CVE-2013-5426) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21660082 Source: XF Type: UNKNOWN ibm-mdmcs-cve20135426-session-hijacking(87535) Source: XF Type: UNKNOWN ibm-infospheremdm-cve20135426-fixation(87535) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |