First published: Thu Mar 03 2016(Updated: )
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Information Steward | =8.5 | |
SAP Information Steward | =8.5.0.1 | |
SAP Information Steward | =8.5.0.2 | |
SAP Information Steward | =8.5.0.3 | |
SAP Information Steward | =8.7 | |
SAP Information Steward | =8.7.0.1 | |
SAP Information Steward | =8.7.0.2 | |
SAP Information Steward | =9.1 | |
SAP Information Steward | =9.1.0.1 | |
SAP Information Steward | =9.1.2 | |
SAP Information Steward | =11.3 | |
SAP Information Steward | =11.3.1 | |
SAP Information Steward | =11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7490 is classified as a medium severity vulnerability allowing access restriction bypass.
To fix CVE-2015-7490, upgrade the IBM InfoSphere Information Server to the latest fixed versions provided by IBM.
CVE-2015-7490 affects users of IBM InfoSphere Information Server versions 8.5 through 11.5.
CVE-2015-7490 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
The potential impacts of CVE-2015-7490 include unauthorized access to sensitive data and functions within IBM InfoSphere Information Server.