PT-2012-5821 · Bigace · Bigace

Yuji Tounai

·

Publicado

2012-11-23

·

Atualizado

2013-04-11

·

CVE-2012-5173

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BIGACE versions prior to 2.7.8
Description A session fixation issue allows remote attackers to hijack web sessions. The exact vectors used for the attack are not specified.
Recommendations For versions prior to 2.7.8, update to version 2.7.8 or later to resolve the issue. As a temporary workaround, consider implementing additional session validation and regeneration mechanisms to minimize the risk of session hijacking.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-5173

Produtos afetados

Bigace