| Vulnerability Name: | CVE-2011-2222 (CCN-69059) | ||||||||
| Assigned: | 2011-08-05 | ||||||||
| Published: | 2011-08-05 | ||||||||
| Updated: | 2015-10-29 | ||||||||
| Summary: | Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors. Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation' | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2011-2222 Source: CCN Type: SA45527 Novell Data Synchronizer Mobility Pack Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 45527 Source: CCN Type: Novell Document ID: 7009054 Session Fixation with Webadmin Source: CONFIRM Type: Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7009054 Source: CCN Type: OSVDB ID: 74520 Novell Data Synchronizer Mobility Pack WebAdmin Unspecified Session Fixation Source: BID Type: UNKNOWN 49069 Source: CCN Type: BID-49069 Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities Source: XF Type: UNKNOWN novell-data-webadmin-session-hijacking(69059) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||