7.5
CVSSv2

CVE-2004-2558

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote malicious users to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli secureway policy director 3.8

ibm websphere everyplace server 2.1.3

ibm tivoli access manager for e-business 3.9

ibm tivoli access manager for e-business 4.1

ibm websphere everyplace server 2.1.4

ibm websphere everyplace server 2.1.5

ibm tivoli access manager for e-business 5.1

ibm tivoli access manager identity manager solution 5.1

ibm tivoli configuration manager 4.2

ibm tivoli configuration manager for atm 2.1