IBM InfoSphere Information Server could allow a malicious user who can login in IIS using their own user id to change the user cookie to another user id to possibly gain access to information that the other user id had access to.
CVEID: CVE-2015-7490
DESCRIPTION: IBM InfoSphere Information Server could allow a malicious user who can login in IIS using their own user id to change the user cookie to another user id to possibly gain access to information that the other user id had access to.
CVSS Base Score: 3.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/108786> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
The following product, running on all supported platforms, is affected:
IBM InfoSphere Information Server: versions 8.5, 8.7, 9.1, 11.3, and 11.5
Product
| VRMF |APAR|Remediation/First Fix
â|â|â|â
InfoSphere Information Server | 11.5 | JR54787 | --Apply IBM InfoSphere Information Server version 11.5.0.1
InfoSphere Information Server | 11.3 | JR54787 | --Apply IBM InfoSphere Information Server version _11.3.1.2 _
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 9.1 | JR54787 | --Apply IBM InfoSphere Information Server version 9.1.2.0
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 8.7 | JR54787 | --Apply IBM InfoSphere Information Server version 8.7 Fix Pack 2
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 8.5 | JR54787 | --Apply IBM InfoSphere Information Server version 8.5 Fix Pack 3
--Apply IBM InfoSphere Information Server Framework Security Patch
Note: The same fix may be listed under multiple vulnerabilities. Installing the fix addresses all vulnerabilities to which the fix applies. Also, some fixes require installing both a fix pack and a subsequent patch. While the fix pack must be installed first, any additional patches required may be installed in any order.
None