PT-2009-6477 · Transware · Transware Active! Mail

Kenichi Maehashi

·

Published

2009-12-17

·

Updated

2017-08-17

·

CVE-2009-4354

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier
Description The issue is related to the improper securing of the session ID in a session cookie, which can be exploited by remote attackers to hijack web sessions. This is likely due to the mishandling of the "secure" flag for cookies in SSL sessions.
Recommendations For TransWARE Active! mail version 2003 build 2003.0139.0871 and earlier, consider disabling the use of session cookies until a proper fix is applied to secure the session ID. As a temporary workaround, restrict access to sensitive areas of the application that rely on secure session management to minimize the risk of session hijacking. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4354

Affected Products

Transware Active! Mail