Lucene search

K
cveIbmCVE-2013-4001
HistoryDec 14, 2013 - 10:55 p.m.

CVE-2013-4001

2013-12-1422:55:02
CWE-287
ibm
web.nvd.nist.gov
24
ibm
cognos
command center
10.2
session fixation
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

53.6%

Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.

Affected configurations

Nvd
Node
ibmcognos_command_centerRange10.1
OR
ibmcognos_command_centerMatch10.0
VendorProductVersionCPE
ibmcognos_command_center*cpe:2.3:a:ibm:cognos_command_center:*:*:*:*:*:*:*:*
ibmcognos_command_center10.0cpe:2.3:a:ibm:cognos_command_center:10.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

53.6%

Related for CVE-2013-4001