CVE-2016-9703

IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.4:*:*:*:*:*:*:*

History

21 Nov 2024, 03:01

Type Values Removed Values Added
References () http://www.ibm.com/support/docview.wss?uid=swg21996761 - Patch, Vendor Advisory () http://www.ibm.com/support/docview.wss?uid=swg21996761 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/95327 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/95327 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037765 - () http://www.securitytracker.com/id/1037765 -

Information

Published : 2017-02-01 22:59

Updated : 2024-11-21 03:01


NVD link : CVE-2016-9703

Mitre link : CVE-2016-9703

CVE.ORG link : CVE-2016-9703


JSON object : View

Products Affected

ibm

  • security_identity_manager_virtual_appliance
CWE
CWE-384

Session Fixation