Lucene search

K
cveIbmCVE-2013-4022
HistorySep 25, 2013 - 10:31 a.m.

CVE-2013-4022

2013-09-2510:31:29
CWE-255
ibm
web.nvd.nist.gov
21
ibm
data studio
optim performance manager
infosphere
optim
configuration manager
db2
recovery expert
authentication
cookie
access restrictions
security vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

35.7%

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.

Affected configurations

Nvd
Node
ibmdata_studio_web_consoleMatch3.1.0
OR
ibmdb2_recovery_expertMatch2.0
OR
ibminfosphere_optim_configuration_managerMatch2.0
OR
ibminfosphere_optim_configuration_managerMatch2.1
OR
ibmoptim_performance_managerMatch5.1.0
VendorProductVersionCPE
ibmdata_studio_web_console3.1.0cpe:2.3:a:ibm:data_studio_web_console:3.1.0:*:*:*:*:*:*:*
ibmdb2_recovery_expert2.0cpe:2.3:a:ibm:db2_recovery_expert:2.0:*:*:*:*:*:*:*
ibminfosphere_optim_configuration_manager2.0cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.0:*:*:*:*:*:*:*
ibminfosphere_optim_configuration_manager2.1cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.1:*:*:*:*:*:*:*
ibmoptim_performance_manager5.1.0cpe:2.3:a:ibm:optim_performance_manager:5.1.0:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

35.7%

Related for CVE-2013-4022