PT-2013-4087 · Ibm · Ibm Security Appscan Enterprise

Published

2013-09-08

·

Updated

2017-08-29

·

CVE-2013-2997

CVSS v2.0

1.7

Low

VectorAV:L/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security AppScan Enterprise versions prior to 8.7
Description The issue allows remote attackers to hijack sessions by leveraging an unattended workstation, due to the failure to invalidate the session context upon a logout action.
Recommendations For versions prior to 8.7, update to version 8.7 or later to resolve the issue. As a temporary workaround, consider implementing a custom session invalidation mechanism upon logout to minimize the risk of session hijacking. Restrict access to workstations to prevent attackers from leveraging unattended machines.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2997

Affected Products

Ibm Security Appscan Enterprise