PT-2014-3244 · Opentext · Opentext Exceed Ondemand

Publicado

2014-05-19

·

Atualizado

2014-05-19

·

CVE-2013-6994

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenText Exceed OnDemand (EoD) version 8
Description The issue allows remote attackers to perform session fixation attacks by sniffing the network, as the session ID is transmitted in cleartext.
Recommendations For version 8, consider implementing encryption for session IDs to prevent them from being intercepted in cleartext, or apply a patch if one becomes available. As a temporary workaround, restrict access to sensitive networks to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6994

Produtos afetados

Opentext Exceed Ondemand