CVE-2004-2558
Gravedad CVSS v2.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
31/12/2004
Última modificación:
03/04/2025
Descripción
*** Pendiente de traducción *** Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
Impacto
Puntuación base 2.0
7.50
Gravedad 2.0
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:ibm:tivoli_access_manager_for_e-business:3.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_access_manager_for_e-business:4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_access_manager_for_e-business:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_access_manager_identity_manager_solution:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_configuration_manager:4.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_configuration_manager_for_atm:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_secureway_policy_director:3.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:websphere_everyplace_server:2.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:websphere_everyplace_server:2.1.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:websphere_everyplace_server:2.1.5:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://secunia.com/advisories/11761
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762
- http://www.securityfocus.com/bid/10449
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16315
- http://secunia.com/advisories/11761
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762
- http://www.securityfocus.com/bid/10449
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16315



