PT-2004-3449 · Ibm · Ibm Access Manager For E-Business+5

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2558

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Tivoli SecureWay Policy Director version 3.8 IBM Access Manager for e-business versions 3.9 through 5.1 IBM Access Manager Identity Manager Solution version 5.1 IBM Configuration Manager version 4.2 IBM Configuration Manager for Automated Teller Machines version 2.1.0 IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms versions 2.1.3 through 2.15
Description The issue allows remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies. This could lead to a potential credential impersonation attack.
Recommendations For IBM Tivoli SecureWay Policy Director version 3.8, update to a version that addresses the issue. For IBM Access Manager for e-business versions 3.9 through 5.1, update to a version that addresses the issue. For IBM Access Manager Identity Manager Solution version 5.1, update to a version that addresses the issue. For IBM Configuration Manager version 4.2, update to a version that addresses the issue. For IBM Configuration Manager for Automated Teller Machines version 2.1.0, update to a version that addresses the issue. For IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms versions 2.1.3 through 2.15, update to a version that addresses the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2558

Affected Products

Ibm Access Manager Identity Manager Solution
Ibm Access Manager For E-Business
Configuration Manager
Ibm Configuration Manager For Automated Teller Machines
Ibm Tivoli Secureway Policy Director
Ibm Websphere Everyplace Server