Session fixation vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.7-P8AE-FP007 allows remote attackers to hijack web sessions via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Filenet_p8_application_engine | Ibm | 4.0.2 (including) | 4.0.2 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-001 (including) | 4.0.2-001 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-002 (including) | 4.0.2-002 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-003 (including) | 4.0.2-003 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-004 (including) | 4.0.2-004 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-005 (including) | 4.0.2-005 (including) |
Filenet_p8_application_engine | Ibm | 4.0.2-006 (including) | 4.0.2-006 (including) |