CVE-2013-4024
Last modified
CVE-2013-4024 is a vulnerability of currently unknown severity. IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Data Studio Web Console | 3.1.0 |
| Ibm | Db2 Recovery Expert | 2.0 |
| Ibm | Infosphere Optim Configuration Manager | 2.0 |
| Ibm | Infosphere Optim Configuration Manager | 2.1 |
| Ibm | Optim Performance Manager | 5.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4024?
How severe is CVE-2013-4024?
How do I fix CVE-2013-4024?
Are you affected by CVE-2013-4024?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
