Vulnerability Bulletins

IBM Security Bulletin: Session Identifier Not Updated vulnerability in GDS component of IBM InfoSphere Master Data Management - Collaborative Edition (CVE-2014-3009)

   
Affected software IBM
 
IBM InfoSphere Master Data Management - Collaborative Edition does not update the session identifier after a successful authentication. An attacker could exploit this vulnerability to gain unauthorized access to the application by acting as the session created by a regular user. CVE(s): CVE-2014-3009 Affected product(s) and affected version(s): IBM InfoSphere Master Data Management - Collaborative Edition Versions 11.3, 11.0, 10.1 and 10.0 – GDS component only. IBM InfoSphere Master

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_session_identifier_not_updated_vulnerability_in_gds_component_of_ibm_infosphere_master_data_management_collaborative_edition_cve_2014_3009?lang=en_us