4.3
CVE-2013-4024
- EPSS 1.07%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Data Studio Web Console Version 3.1.0
Ibm ≫ Db2 Recovery Expert Version 2.0
Ibm ≫ Infosphere Optim Configuration Manager Version 2.0
Ibm ≫ Infosphere Optim Configuration Manager Version 2.1
Ibm ≫ Optim Performance Manager Version 5.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.07% | 0.604 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www-01.ibm.com/support/docview.wss?uid=swg21650504
https://exchange.xforce.ibmcloud.com/vulnerabilities/85931