Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
References
Link | Resource |
---|---|
http://secunia.com/advisories/35931 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg24023826 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/35779 | Patch |
http://www.securitytracker.com/id?1022597 | |
http://www.vupen.com/english/advisories/2009/1990 | Patch Vendor Advisory |
http://secunia.com/advisories/35931 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg24023826 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/35779 | Patch |
http://www.securitytracker.com/id?1022597 | |
http://www.vupen.com/english/advisories/2009/1990 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 01:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/35931 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg24023826 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/35779 - Patch | |
References | () http://www.securitytracker.com/id?1022597 - | |
References | () http://www.vupen.com/english/advisories/2009/1990 - Patch, Vendor Advisory |
Information
Published : 2009-07-23 20:30
Updated : 2024-11-21 01:05
NVD link : CVE-2009-2583
Mitre link : CVE-2009-2583
CVE.ORG link : CVE-2009-2583
JSON object : View
Products Affected
ibm
- tivoli_identity_manager
CWE
CWE-20
Improper Input Validation