Affected configuration(s):


Date published: 2014-02-14T08:10:48.623-05:00

Date last modified: 2014-02-21T00:06:31.983-05:00

CVSS Score: 5.1

Principal attack vector: NETWORK

Complexity:  HIGH

Reference URL:

Summary: CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.


Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.