CVE Database
/

CVE-2013-2994

Back to search

CVE-2013-2994

Published: Jul 31, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

JR45420
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now