7.5
CVE-2004-2558
- EPSS 0.78%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Tivoli Access Manager For E-business Version3.9
Ibm ≫ Tivoli Access Manager For E-business Version4.1
Ibm ≫ Tivoli Access Manager For E-business Version5.1
Ibm ≫ Tivoli Access Manager Identity Manager Solution Version5.1
Ibm ≫ Tivoli Configuration Manager Version4.2
Ibm ≫ Tivoli Configuration Manager For Atm Version2.1
Ibm ≫ Tivoli Secureway Policy Director Version3.8
Ibm ≫ Websphere Everyplace Server Version2.1.3
Ibm ≫ Websphere Everyplace Server Version2.1.4
Ibm ≫ Websphere Everyplace Server Version2.1.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.78% | 0.714 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|