PT-2009-5928 · Unknown · Shared Sign-On

Publicado

2009-10-09

·

Atualizado

2017-08-17

·

CVE-2009-3656

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Shared Sign-On versions 5.x through 6.x
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of arbitrary users. This is achieved via unknown vectors, potentially allowing for unauthorized access to user accounts.
Recommendations For versions 5.x through 6.x, update to a version that includes a fix for this issue to prevent CSRF attacks.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3656

Produtos afetados

Shared Sign-On