8.1

CVE-2016-9981

IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257

Data is provided by the National Vulnerability Database (NVD)
IbmSecurity Appscan Version9.0.0.0 SwEditionenterprise
IbmSecurity Appscan Version9.0.0.1 SwEditionenterprise
IbmSecurity Appscan Version9.0.1.0 SwEditionenterprise
IbmSecurity Appscan Version9.0.1.1 SwEditionenterprise
IbmSecurity Appscan Version9.0.2.0 SwEditionenterprise
IbmSecurity Appscan Version9.0.2.1 SwEditionenterprise
IbmSecurity Appscan Version9.0.3.0 SwEditionenterprise
IbmSecurity Appscan Version9.0.3.1 SwEditionenterprise
IbmSecurity Appscan Version9.0.3.4 SwEditionenterprise
IbmSecurity Appscan Version9.0.3.5 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.609
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.