PT-2009-6476 · Transware · Transware Active! Mail

Kenichi Maehashi

·

Published

2009-12-17

·

Updated

2017-08-17

·

CVE-2009-4353

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions TransWARE Active! mail 2003 versions 2003.0139.0871 and earlier
Description The issue allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL, due to the failure to remove the session ID in a Referer URL.
Recommendations For TransWARE Active! mail 2003 versions 2003.0139.0871 and earlier, consider disabling the use of Referer URLs until a patch is available to remove the session ID and prevent web session hijacking.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-4353

Affected Products

Transware Active! Mail