PT-2014-3244 · Opentext · Opentext Exceed Ondemand

Published

2014-05-19

·

Updated

2014-05-19

·

CVE-2013-6994

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenText Exceed OnDemand (EoD) version 8
Description The issue allows remote attackers to perform session fixation attacks by sniffing the network, as the session ID is transmitted in cleartext.
Recommendations For version 8, consider implementing encryption for session IDs to prevent them from being intercepted in cleartext, or apply a patch if one becomes available. As a temporary workaround, restrict access to sensitive networks to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6994

Affected Products

Opentext Exceed Ondemand