CVE-2004-2558: High severity IBM Tivoli Access Manager for e-business vulnerability
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2558?
CVE-2004-2558 is classified as a moderate severity vulnerability.
How do I fix CVE-2004-2558?
To fix CVE-2004-2558, upgrade the affected software to the latest patched version provided by IBM.
Which software is affected by CVE-2004-2558?
CVE-2004-2558 affects IBM Tivoli SecureWay Policy Director, IBM Tivoli Access Manager for e-business, IBM WebSphere Everyplace Server, and other IBM products listed in the CVE.
Is CVE-2004-2558 exploitable remotely?
Yes, CVE-2004-2558 can potentially be exploited remotely, impacting the security of the affected systems.
When was CVE-2004-2558 disclosed?
CVE-2004-2558 was disclosed on December 20, 2004.