First published: Mon Apr 06 2015(Updated: )
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.1.0.0 | |
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.1.0.1 | |
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1893 has a high severity rating due to its potential for session hijacking and data compromise.
To fix CVE-2015-1893, upgrade the IBM WebSphere DataPower XC10 appliance to version 2.1.0.3 or later.
CVE-2015-1893 allows remote attackers to hijack user sessions and access sensitive information.
Versions 2.1.0.0, 2.1.0.1, and 2.1.0.2 of the IBM WebSphere DataPower XC10 appliance are affected by CVE-2015-1893.
Yes, CVE-2015-1893 can allow attackers to modify data by hijacking user sessions.