CVE-2013-2994
01.08.2013, 13:32
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | websphere_commerce | 7.0:feature_pack4 |
ibm | websphere_commerce | 7.0:feature_pack5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References