CVE-2014-9386

Published Dec 15, 2014

Last updated 9 years ago

Overview

Description
Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
Source
cret@cert.org
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.4
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
<a href="http://cwe.mitre.org/data/definitions/384.html" target="_blank">CWE-384: Session Fixation</a>
Impact
-
Solution
-

Vendor comments

  • ZenossAddressed in versions 5.0, 4.2.5.SP273, and 4.2.4.SP854

Configurations