PT-2009-6477 · Transware · Transware Active! Mail

Kenichi Maehashi

·

Publicado

2009-12-17

·

Atualizado

2017-08-17

·

CVE-2009-4354

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier
Description The issue is related to the improper securing of the session ID in a session cookie, which can be exploited by remote attackers to hijack web sessions. This is likely due to the mishandling of the "secure" flag for cookies in SSL sessions.
Recommendations For TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier, consider disabling the use of session cookies until a proper fix is applied to secure the session ID. As a temporary workaround, restrict access to sensitive areas of the application that rely on secure session management to minimize the risk of session hijacking. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4354

Produtos afetados

Transware Active! Mail