IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1JR45420 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21644393 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/84033 - |
Information
Published : 2013-08-01 13:32
Updated : 2024-11-21 01:52
NVD link : CVE-2013-2994
Mitre link : CVE-2013-2994
CVE.ORG link : CVE-2013-2994
JSON object : View
Products Affected
ibm
- websphere_commerce
CWE
CWE-20
Improper Input Validation