VulnerabilityModified
CVE-2015-7490
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
LOW 3.1EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
- CVSS 3.0
- 3.1 LOWCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/infosphere information server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54787Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21975827Vendor Advisory
- http://www.securitytracker.com/id/1035125
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54787Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21975827Vendor Advisory
- http://www.securitytracker.com/id/1035125
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.