CVE-2013-4022

I

BM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:data_studio_web_console:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_recovery_expert:2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:optim_performance_manager:5.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:54

Type Values Removed Values Added
References () http://www-01.ibm.com/support/docview.wss?uid=swg21650504 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21650504 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/85928 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/85928 -

Information

Published : 2013-09-25 10:31

Updated : 2025-04-11 00:51


NVD link : CVE-2013-4022

Mitre link : CVE-2013-4022

CVE.ORG link : CVE-2013-4022


JSON object : View

CWE
CWE-255

Credentials Management Errors