IBM Multiple Product Unspecified Credential Impersonation Vulnerability
BID:10449
Info
IBM Multiple Product Unspecified Credential Impersonation Vulnerability
| Bugtraq ID: | 10449 |
| Class: | Unknown |
| CVE: |
CVE-2004-2558 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2004 12:00AM |
| Updated: | Jun 02 2004 12:00AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
IBM WebSphere Everyplace Server 2.15 IBM WebSphere Everyplace Server 2.14 IBM WebSphere Everyplace Server 2.1.3 IBM Tivoli SecureWay Policy Director 3.8 IBM Tivoli Configuration Manager for ATM 2.1 IBM Tivoli Configuration Manager 4.2 IBM Tivoli Access Manager Identity Manager Solution 5.1 IBM Tivoli Access Manager for e-business 5.1 IBM Tivoli Access Manager for e-business 4.1 IBM Tivoli Access Manager for e-business 3.9 |
| Not Vulnerable: | |
Discussion
IBM Multiple Product Unspecified Credential Impersonation Vulnerability
Multiple IBM products are prone to an unspecified credential impersonation vulnerability.
According to IBM this vulnerability may allow a remote attacker to gain access to resources and data, or gain control of the compromised application. It is reported that this attack can allow the attacker to exploit the usage of cookies and impersonate a legitimate user to gain unauthorized access.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
Multiple IBM products are prone to an unspecified credential impersonation vulnerability.
According to IBM this vulnerability may allow a remote attacker to gain access to resources and data, or gain control of the compromised application. It is reported that this attack can allow the attacker to exploit the usage of cookies and impersonate a legitimate user to gain unauthorized access.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
Exploit / POC
IBM Multiple Product Unspecified Credential Impersonation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM Multiple Product Unspecified Credential Impersonation Vulnerability
Solution:
WebSphere Everyplace Server fixes can be obtained by contacting the vendor.
IBM fixes are available:
IBM Tivoli Configuration Manager for ATM 2.1
IBM Tivoli Access Manager for e-business 3.9
IBM Tivoli Configuration Manager 4.2
Solution:
WebSphere Everyplace Server fixes can be obtained by contacting the vendor.
IBM fixes are available:
IBM Tivoli Configuration Manager for ATM 2.1
-
IBM 3.8-PWS-0016
WebSEAL.
http://www-1.ibm.com/support/docview.wss?uid=swg24006478
IBM Tivoli Access Manager for e-business 3.9
-
IBM 3.9-WPI-0005
Web Server Plug-in.
http://www-1.ibm.com/support/docview.wss?uid=swg24006535
IBM Tivoli Configuration Manager 4.2
-
IBM 3.8-PWS-0016
WebSEAL.
http://www-1.ibm.com/support/docview.wss?uid=swg24006478
References
IBM Multiple Product Unspecified Credential Impersonation Vulnerability
References:
References: