Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/23988 | vdb entry |
http://www.vupen.com/english/advisories/2007/1823 | vdb entry |
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01049713 | vendor advisory |
http://osvdb.org/36061 | vdb entry |
http://www.securityfocus.com/archive/1/468974/100/0/threaded | mailing list |
http://www.acrossecurity.com/aspr/ASPR-2007-05-14-1-PUB.txt | patch |
http://www.securitytracker.com/id?1018062 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34303 | vdb entry |
http://secunia.com/advisories/25275 | third party advisory vendor advisory |