CVE-2013-4091: Imperva Securesphere
High severity, CVSS 7.5. EPSS: 5.6% chance of exploitation in the next 30 days.
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Affected products
- Imperva Securesphere: version 9.0.0.5 only
Published 2013-06-28. Last modified 2026-06-16.