IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Infosphere_information_server | Ibm | 8.1 (including) | 8.1 (including) |
Infosphere_information_server | Ibm | 8.5 (including) | 8.5 (including) |
Infosphere_information_server | Ibm | 8.7 (including) | 8.7 (including) |
Infosphere_information_server | Ibm | 9.1 (including) | 9.1 (including) |
Such a scenario is commonly observed when: