Vulnerability Name: | CVE-2014-9015 (CCN-98860) | ||||||||||||||||||||||||||||
Assigned: | 2014-11-20 | ||||||||||||||||||||||||||||
Published: | 2014-11-20 | ||||||||||||||||||||||||||||
Updated: | 2018-12-20 | ||||||||||||||||||||||||||||
Summary: | Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Informational | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-9015 Source: CCN Type: oss-security Mailing List, Thu, 20 Nov 2014 07:10:28 +0100 Pending CVE assignments for SA-CORE-2014-006? Source: CCN Type: oss-security Mailing List, Thu, 20 Nov 2014 09:48:17 -0500 (EST) Re: Pending CVE assignments for SA-CORE-2014-006? Source: SECUNIA Type: Third Party Advisory 59164 Source: SECUNIA Type: Third Party Advisory 59814 Source: DEBIAN Type: Third Party Advisory DSA-3075 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006? Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20141120 Pending CVE assignments for SA-CORE-2014-006? Source: CCN Type: BID-71195 Drupal Core CVE-2014-9015 Session Hijacking Vulnerability Source: XF Type: UNKNOWN drupalcore-cve20149015-session-hijacking(98860) Source: CCN Type: DRUPAL-SA-CORE-2014-006 Drupal Core - Moderately Critical - Multiple Vulnerabilities Source: CONFIRM Type: Vendor Advisory https://www.drupal.org/SA-CORE-2014-006 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-9015 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |