First published: Thu Dec 19 2013(Updated: )
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Master Data Management Collaborative Server | =10.0 | |
IBM InfoSphere Master Data Management Collaborative Server | =10.1 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.0 | |
IBM InfoSphere Master Data Management Server for Product Information Management | =9.0 | |
IBM InfoSphere Master Data Management Server for Product Information Management | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5426 is classified as a medium severity vulnerability.
To fix CVE-2013-5426, upgrade to IBM InfoSphere Master Data Management Collaborative Edition version 10.1 IF5, 11.0 IF1, or 9.1 IF11.
CVE-2013-5426 affects users of IBM InfoSphere Master Data Management Collaborative Edition versions before 10.1 IF5 and 11.0 IF1, and the Master Data Management Server for Product Information Management versions before 9.1 IF11.
A session fixation vulnerability, such as CVE-2013-5426, allows attackers to hijack or take over valid user sessions to gain unauthorized access.
Yes, CVE-2013-5426 can be exploited by remote authenticated users to hijack web sessions.