First published: Thu Aug 01 2013(Updated: )
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0-feature_pack4 | |
IBM WebSphere Commerce | =7.0-feature_pack5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.