PT-2008-5556 · Ibm · Ibm Tivoli Netcool/Webtop

Publicado

2008-09-27

·

Atualizado

2017-08-08

·

CVE-2008-4294

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IBM Tivoli Netcool/Webtop versions 2.1 through 2.1.0.4
Description: The issue allows physically proximate attackers to hijack a session by visiting an unattended workstation, because cached user privileges are preserved after logout. This can be demonstrated by a root session that remains valid after a subsequent read-only session has begun.
Recommendations: For IBM Tivoli Netcool/Webtop versions 2.1 through 2.1.0.4, update to version 2.1.0.5 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4294

Produtos afetados

Ibm Tivoli Netcool/Webtop