IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
BID:61760
Info
IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
| Bugtraq ID: | 61760 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-0497 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2013 12:00AM |
| Updated: | Jun 28 2013 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Storwize V7000 Unified 1.4 1 IBM Storwize V7000 Unified 1.4 0 IBM Storwize V7000 Unified 1.3.2 3 IBM Storwize V7000 Unified 1.3.2 1 IBM Storwize V7000 Unified 1.3.2 0 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Scale Out Network Attached Storage 1.3.2 1-21 IBM Scale Out Network Attached Storage 1.3.2 1-20 IBM Scale Out Network Attached Storage 1.3.2 IBM Scale Out Network Attached Storage 1.3.1 IBM Scale Out Network Attached Storage 1.3.2.3 IBM Scale Out Network Attached Storage 1.3.2.2 IBM Scale Out Network Attached Storage 1.3.0.5 IBM Scale Out Network Attached Storage 1.3.0.4 |
| Not Vulnerable: |
IBM Storwize V7000 Unified 1.4.1.0 IBM Scale Out Network Attached Storage 1.4.1.0 |
Discussion
IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
IBM SONAS and Storwize V7000 Unified are prone to a session-hijacking vulnerability.
Successful exploits may allow an attacker to gain unauthorized access to the affected application.
IBM SONAS and Storwize V7000 Unified are prone to a session-hijacking vulnerability.
Successful exploits may allow an attacker to gain unauthorized access to the affected application.
Exploit / POC
IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM SONAS and Storwize V7000 Unified CVE-2013-0497 Session Hijacking Vulnerability
References:
References: