CVE-2014-1219CVE-2014-1219

Affected configuration(s):

cpe:/a:ca:2e_web_option:r8.1.2

Date published: 2014-02-14T08:10:48.623-05:00

Date last modified: 2014-02-21T00:06:31.983-05:00

CVSS Score: 5.1

Principal attack vector: NETWORK

Complexity:  HIGH

Reference URL: http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1219/

Summary: CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.