CVE-2004-2558
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- ibm/tivoli access manager for e-business · ibm/tivoli access manager identity manager solution · ibm/tivoli configuration manager · ibm/tivoli configuration manager for atm · ibm/tivoli secureway policy director · ibm/websphere everyplace server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/11761Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10449Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16315
- http://secunia.com/advisories/11761Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10449Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16315
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.