PT-2009-4409 · Ibm · Ibm Filenet Content Manager
Publicado
2009-06-06
·
Atualizado
2013-01-29
·
CVE-2009-1953
CVSS v2.0
4.6
Média
| Vetor | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
IBM FileNet Content Manager versions 4.0 through 4.5
Description:
The issue arises when the CE Web Services listener has a certain WSEAF configuration, allowing remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors. This occurs due to the improper restriction of a cached Subject.
Recommendations:
For IBM FileNet Content Manager versions 4.0 through 4.5, consider reconfiguring the CE Web Services listener to properly restrict the use of cached Subjects until a patch is available. Restrict access to the affected WSEAF configuration to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Filenet Content Manager