CVE Vulnerabilities

CVE-2004-2558

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka Potential Credential Impersonation Attack.

Affected Software

NameVendorStart VersionEnd Version
Tivoli_access_manager_for_e-businessIbm3.9 (including)3.9 (including)
Tivoli_access_manager_for_e-businessIbm4.1 (including)4.1 (including)
Tivoli_access_manager_for_e-businessIbm5.1 (including)5.1 (including)
Tivoli_access_manager_identity_manager_solutionIbm5.1 (including)5.1 (including)
Tivoli_configuration_managerIbm4.2 (including)4.2 (including)
Tivoli_configuration_manager_for_atmIbm2.1 (including)2.1 (including)
Tivoli_secureway_policy_directorIbm3.8 (including)3.8 (including)
Websphere_everyplace_serverIbm2.1.3 (including)2.1.3 (including)
Websphere_everyplace_serverIbm2.1.4 (including)2.1.4 (including)
Websphere_everyplace_serverIbm2.1.5 (including)2.1.5 (including)

References