CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.4. It may be remotely exploitable.
CVE
CVE-2013-2994
Severity
MEDIUM
CVSS
6.4
EPSS
1.32%
Original NVD Description
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.