PT-2009-6477 · Transware · Transware Active! Mail
Kenichi Maehashi
·
Publicado
2009-12-17
·
Atualizado
2017-08-17
·
CVE-2009-4354
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier
Description
The issue is related to the improper securing of the session ID in a session cookie, which can be exploited by remote attackers to hijack web sessions. This is likely due to the mishandling of the "secure" flag for cookies in SSL sessions.
Recommendations
For TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier, consider disabling the use of session cookies until a proper fix is applied to secure the session ID. As a temporary workaround, restrict access to sensitive areas of the application that rely on secure session management to minimize the risk of session hijacking. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Transware Active! Mail