7.2

CVE-2008-4294

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Tivoli Netcool Webtop Version 2.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/32036
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg24018932
Patch
http://www.vupen.com/english/advisories/2008/2690
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ21888
http://www.securityfocus.com/bid/31414
https://exchange.xforce.ibmcloud.com/vulnerabilities/45419