IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rational_appscan | Ibm | 5.2 (including) | 5.2 (including) |
Rational_appscan | Ibm | 5.4 (including) | 5.4 (including) |
Rational_appscan | Ibm | 5.5.0 (including) | 5.5.0 (including) |
Rational_appscan | Ibm | 5.5.0.1 (including) | 5.5.0.1 (including) |
Rational_appscan | Ibm | 5.5.0.2 (including) | 5.5.0.2 (including) |
Rational_appscan | Ibm | 5.6.0 (including) | 5.6.0 (including) |
Rational_appscan | Ibm | 5.6.0.3 (including) | 5.6.0.3 (including) |
Rational_appscan | Ibm | 8.0.0 (including) | 8.0.0 (including) |
Rational_appscan | Ibm | 8.0.0.1 (including) | 8.0.0.1 (including) |
Rational_appscan | Ibm | 8.0.0.2 (including) | 8.0.0.2 (including) |
Rational_appscan | Ibm | 8.0.0.3 (including) | 8.0.0.3 (including) |
Rational_appscan | Ibm | 8.0.1 (including) | 8.0.1 (including) |
Rational_appscan | Ibm | 8.0.1.1 (including) | 8.0.1.1 (including) |
Rational_appscan | Ibm | 8.5.0 (including) | 8.5.0 (including) |
Rational_appscan | Ibm | 8.5.0.0 (including) | 8.5.0.0 (including) |