4

CVE-2013-5450

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

Data is provided by the National Vulnerability Database (NVD)
IbmSecurity Appscan Version8.5.0.0 Update- Editionenterprise
IbmSecurity Appscan Version8.5.0.1 Update- Editionenterprise
IbmSecurity Appscan Version8.6.0.0 Update- Editionenterprise
IbmSecurity Appscan Version8.6.0.1 Update- Editionenterprise
IbmSecurity Appscan Version8.6.0.2 Update- Editionenterprise
IbmSecurity Appscan Version8.7.0.0 Update- Editionenterprise
IbmSecurity Appscan Version8.7.0.1 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.388
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N