Описание
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.8.0 (исключая)
cpe:2.3:a:rws:worldserver:*:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02504
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-331
Связанные уязвимости
CVSS3: 5.3
github
больше 2 лет назад
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
EPSS
Процентиль: 85%
0.02504
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-331