Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg24023826 | Patch Vendor Advisory |
http://www.vupen.com/english/advisories/2009/1990 | Patch Vendor Advisory |
http://secunia.com/advisories/35931 | Vendor Advisory |
http://www.securityfocus.com/bid/35779 | Patch |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659 | Vendor Advisory |
http://www.securitytracker.com/id?1022597 |
Configurations
Information
Published : 2009-07-23 13:30
Updated : 2009-08-03 22:25
NVD link : CVE-2009-2583
Mitre link : CVE-2009-2583
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
ibm
- tivoli_identity_manager