CVE-2013-4001: Medium severity IBM Cognos Command Center vulnerability
Published Dec 14, 2013
·Updated
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
Affected Software
2 affected components
IBM Cognos Command Center<=10.1
IBM Cognos Command Center=10.0
Event History
Dec 14, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4001?
CVE-2013-4001 has a medium severity level as it allows remote attackers to hijack web sessions.
2
How do I fix CVE-2013-4001?
To fix CVE-2013-4001, upgrade IBM Cognos Command Center to version 10.2 or later.
3
Which versions of IBM Cognos Command Center are affected by CVE-2013-4001?
CVE-2013-4001 affects IBM Cognos Command Center versions 10.0 and 10.1.
4
What type of vulnerability is CVE-2013-4001?
CVE-2013-4001 is a session fixation vulnerability that allows web session hijacking.
5
Can CVE-2013-4001 be exploited remotely?
Yes, CVE-2013-4001 can be exploited remotely by attackers through an authorization cookie.