PT-2009-6319 · Best Practical Solutions · Rt

Publicado

2009-12-02

·

Atualizado

2017-08-17

·

CVE-2009-4151

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Best Practical Solutions RT versions 3.0.0 through 3.6.9 Best Practical Solutions RT versions 3.8.x through 3.8.5
Description A session fixation issue allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages HTTP access to the RT server.
Recommendations For versions 3.0.0 through 3.6.9, update to a version outside of this range to resolve the issue. For versions 3.8.x through 3.8.5, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting HTTP access to the RT server to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4151
DSA-1944-1

Produtos afetados

Rt