CVE-2009-2583
CVE-2009-2583 is a medium-severity vulnerability in Ibm Tivoli Identity Manager with a CVSS 2.0 base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.8)
- EPSS exploit prediction: 1% (70th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Ibm Tivoli Identity Manager
- Published:
- Last modified:
Description
Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
Frequently asked questions
- What is CVE-2009-2583?
- Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
- How severe is CVE-2009-2583?
- CVE-2009-2583 has a CVSS 2.0 base score of 6.8, rated medium severity.
- Is CVE-2009-2583 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (70th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2009-2583?
- CVE-2009-2583 affects Ibm Tivoli Identity Manager. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2009-2583?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2009-2583 published?
- CVE-2009-2583 was published on 2009-07-23 and last updated on 2026-06-16.
References
- http://secunia.com/advisories/35931
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659
- http://www-01.ibm.com/support/docview.wss?uid=swg24023826
- http://www.securityfocus.com/bid/35779
- http://www.securitytracker.com/id?1022597
- http://www.vupen.com/english/advisories/2009/1990
Affected products (1)
- cpe:2.3:a:ibm:tivoli_identity_manager:5.0.0.6:*:*:*:*:*:*:*
More vulnerabilities in Ibm Tivoli Identity Manager
- CVE-2014-6111 — High (CVSS 7.8): IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before…
- CVE-2014-0961 — Medium (CVSS 6.0): Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1…
- CVE-2014-6112 — Medium (CVSS 5.9): IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before…
- CVE-2014-6108 — Medium (CVSS 5.9): IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before…
- CVE-2014-6109 — Medium (CVSS 5.3): IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before…
- CVE-2009-2316 — Medium (CVSS 4.3): Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to…
All CVEs affecting Ibm Tivoli Identity Manager →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →