Session Fixation Vulnerability in IBM Cognos Command Center
CVE-2013-4001

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 December 2013

Summary

A session fixation vulnerability exists in IBM Cognos Command Center versions prior to 10.2, allowing remote attackers to hijack active web sessions. This vulnerability can be exploited via manipulation of an authorization cookie, which, if intercepted or controlled by an attacker, grants unauthorized access to user sessions, potentially leading to sensitive data exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.