IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21650504 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85931 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2013-09-25T10:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2013-06-07T00:00:00
Link: CVE-2013-4024
JSON object: View
NVD Information
Status : Modified
Published: 2013-09-25T10:31:29.127
Modified: 2017-08-29T01:33:33.027
Link: CVE-2013-4024
JSON object: View
Redhat Information
No data.
CWE