Описание
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
Ссылки
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.0 (включая)Версия от 3.0.0 (включая) до 3.1.0 (включая)
Одно из
cpe:2.3:a:cybozu:remote_service_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cybozu:remote_service_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00555
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
EPSS
Процентиль: 68%
0.00555
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287