Session Fixation Vulnerability in IBM Cognos Command Center
CVE-2013-4001
Currently unrated
Summary
A session fixation vulnerability exists in IBM Cognos Command Center versions prior to 10.2, allowing remote attackers to hijack active web sessions. This vulnerability can be exploited via manipulation of an authorization cookie, which, if intercepted or controlled by an attacker, grants unauthorized access to user sessions, potentially leading to sensitive data exposure.
References
Timeline
Vulnerability published
Vulnerability Reserved