Vulnerability Bulletins

IBM Security Bulletin: Insecure Transmission Vulnerability with IBM InfoSphere Information Server (CVE-2015-7490)

   
Affected software IBM
 
IBM InfoSphere Information Server could allow a malicious user who can login in IIS using their own user id to change the user cookie to another user id to possibly gain access to information that the other user id had access to. CVE(s): CVE-2015-7490Affected product(s) and affected version(s):The following product, running on all supported platforms, is affected: IBM InfoSphere Information Server: versions 8.5, 8.7, 9.1, 11.3, and 11.5 Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_insecure_transmission_vulnerability_with_ibm_infosphere_information_server_cve_2015_7490?lang=en_us