PT-2016-1413 · Ibm · Ibm Infosphere Information Server
Publicado
2016-03-03
·
Atualizado
2017-09-08
·
CVE-2015-7490
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Information Server versions 8.5 through FP3
IBM InfoSphere Information Server versions 8.7 through FP2
IBM InfoSphere Information Server versions 9.1 through 9.1.2.0
IBM InfoSphere Information Server versions 11.3 through 11.3.1.2
IBM InfoSphere Information Server versions 11.5
Description
The issue is related to insufficient access control in the InfoSphere Information Server platform. It allows a remote authenticated user to bypass intended access restrictions by using a modified cookie.
Recommendations
For IBM InfoSphere Information Server versions 8.5 through FP3, update to a version later than FP3 to resolve the issue.
For IBM InfoSphere Information Server versions 8.7 through FP2, update to a version later than FP2 to resolve the issue.
For IBM InfoSphere Information Server versions 9.1 through 9.1.2.0, update to a version later than 9.1.2.0 to resolve the issue.
For IBM InfoSphere Information Server versions 11.3 through 11.3.1.2, update to a version later than 11.3.1.2 to resolve the issue.
For IBM InfoSphere Information Server versions 11.5, update to a version later than 11.5 to resolve the issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Infosphere Information Server