First published: Wed Oct 02 2013(Updated: )
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Server | =8.0 | |
IBM InfoSphere Information Server | =8.1 | |
IBM InfoSphere Information Server | =8.5 | |
IBM InfoSphere Information Server | =8.5.0.1 | |
IBM InfoSphere Information Server | =8.5.0.2 | |
IBM InfoSphere Information Server | =8.5.0.3 | |
IBM InfoSphere Information Server | =8.7 | |
IBM InfoSphere Information Server | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4067 is considered a high severity vulnerability due to its potential for session hijacking and credential theft.
To mitigate CVE-2013-4067, apply the latest security patches provided by IBM for affected versions of InfoSphere Information Server.
CVE-2013-4067 affects IBM InfoSphere Information Server versions 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1.
CVE-2013-4067 can be exploited for remote session hijacking and phishing attacks that aim to capture user credentials.
There have been reports indicating that CVE-2013-4067 has the potential for active exploitation, emphasizing the importance of applying security updates.