Описание
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.47 (включая)Версия до 8.47 (включая)
Одно из
cpe:2.3:a:ca:unified_infrastructure_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:unified_infrastructure_management_snap:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.0124
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.
EPSS
Процентиль: 79%
0.0124
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200