Security Bulletin: Information disclosure vulnerability in IBM Security AppScan Standard (CVE-2013-0510)
IBM PSIRT 270004PFE3 email@example.com | | Tags:  psirtsecurity psirtmedium
0 Comments | 763 Visits
One of the AppScan security tests will inadvertently forward session cookies to a hardcoded IBM owned external server. A man in the middle attack or a compromise of the external server could lead to sensitive cookie information being revealed. This could lead to takeover of the test account being used for scanning. Specific knowledge of AppScan Standard is necessary to conduct the attack. The attack can be conducted over the internet. No authentication is required for the attack.
Affected product(s) & Affected version(s):
· Versions 8.6 through 22.214.171.124 of Security AppScan Standard running on Microsoft Windows
Refer to the following reference URLs for remediation and additional vulnerability details.
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21631303
X-Force Database: http://xforce.iss.net/xforce/xfdb/82592