CVE-2004-2558
Last modified
CVE-2004-2558 is a vulnerability of currently unknown severity. Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack.". EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Access Manager For E-Business | 3.9 |
| Ibm | Tivoli Access Manager For E-Business | 4.1 |
| Ibm | Tivoli Access Manager For E-Business | 5.1 |
| Ibm | Tivoli Access Manager Identity Manager Solution | 5.1 |
| Ibm | Tivoli Configuration Manager | 4.2 |
| Ibm | Tivoli Configuration Manager For Atm | 2.1 |
| Ibm | Tivoli Secureway Policy Director | 3.8 |
| Ibm | Websphere Everyplace Server | 2.1.3 |
| Ibm | Websphere Everyplace Server | 2.1.4 |
| Ibm | Websphere Everyplace Server | 2.1.5 |
References
- http://secunia.com/advisories/11761Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762Patch, Vendor Advisory
- http://secunia.com/advisories/11761Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21168762Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2558?
How severe is CVE-2004-2558?
How do I fix CVE-2004-2558?
Are you affected by CVE-2004-2558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
