IBM WebSphere DataPower Input Validation Bug Lets Remote Users Hijack Sessions
|
SecurityTracker Alert ID: 1032025 |
SecurityTracker URL: http://securitytracker.com/id/1032025
|
CVE Reference:
CVE-2015-1893
(Links to External Site)
|
Date: Apr 6 2015
|
Impact:
User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): Model XC10; 2.1
|
Description:
A vulnerability was reported in IBM WebSphere DataPower. A remote user can hijack the target user's session.
The system does not properly validate input. A remote user can hijack a valid user's session and gain the privileges of the target user.
|
Impact:
A remote user can hijack a target user's session.
|
Solution:
The vendor has issued a fix (2.1.0.3; APAR IT07841).
The vendor's advisory is available at:
http://www-01.ibm.com/support/docview.wss?uid=swg21701337
|
Vendor URL: www-01.ibm.com/support/docview.wss?uid=swg21701337 (Links to External Site)
|
Cause:
Input validation error
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|