CVE-2012-2735

Published Sep 28, 2012

Last updated 2 years ago

Overview

Description
Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
4.9
Impact score
4.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'
Impact
Per: http://rhn.redhat.com/errata/RHSA-2012-1278.html " An authenticated user able to pre-set the Cumin session cookie in a victim's browser could possibly use this flaw to steal the victim's session after they log into Cumin."
Solution
Per: http://rhn.redhat.com/errata/RHSA-2012-1278.html " An authenticated user able to pre-set the Cumin session cookie in a victim's browser could possibly use this flaw to steal the victim's session after they log into Cumin."

Configurations