Date published: 2014-02-14T08:10:48.623-05:00
Date last modified: 2014-02-21T00:06:31.983-05:00
CVSS Score: 5.1
Principal attack vector: NETWORK
Reference URL: http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1219/
Summary: CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.