First published: Thu Aug 01 2013(Updated: )
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0-feature_pack4 | |
IBM WebSphere Commerce | =7.0-feature_pack5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2994 is classified as a medium severity vulnerability.
To mitigate CVE-2013-2994, update IBM WebSphere Commerce to a version that incorporates patches for this vulnerability.
CVE-2013-2994 affects IBM WebSphere Commerce version 7.0 Feature Pack 4 and Feature Pack 5.
CVE-2013-2994 allows remote attackers to issue REST requests in the context of an arbitrary user's active session.
CVE-2013-2994 allows exploitation without requiring user authentication, as it maintains a valid session after certain interactions.