CVE Vulnerabilities

CVE-2013-5426

Improper Authentication

Published: Dec 19, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:A/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Infosphere_master_data_management_collaboration_serverIbm10.0 (including)10.0 (including)
Infosphere_master_data_management_collaboration_serverIbm10.1 (including)10.1 (including)
Infosphere_master_data_management_collaboration_serverIbm11.0 (including)11.0 (including)
Infosphere_master_data_management_server_for_product_information_managementIbm9.0 (including)9.0 (including)
Infosphere_master_data_management_server_for_product_information_managementIbm9.1 (including)9.1 (including)

Potential Mitigations

References