CVE-2013-4092
Imperva Securesphere - Credentials Management
Title source: ruleDescription
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a session ID in the jsessionid field to secsphLogin.jsp or (2) credentials in the j_password parameter to j_acegi_security_check, and reading (a) web-server access logs, (b) web-server Referer logs, or (c) the browser history.
Exploits (1)
Scores
EPSS
0.0600
EPSS Percentile
90.7%
Details
CWE
CWE-255
Status
published
Products (1)
imperva/securesphere
9.0.0.5
Published
Jun 28, 2013
Tracked Since
Feb 18, 2026