CVE-2020-15910
Summary
| CVE | CVE-2020-15910 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-19 13:15:00 UTC |
| Updated | 2020-10-29 22:16:00 UTC |
| Description | SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | N-central | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| limenetworks.nl/wp-content/uploads/CVE-934261-v-1.2.pdf | MISC | limenetworks.nl | Third Party Advisory |
| MSP N-central | SolarWinds MSP | MISC | www.solarwindsmsp.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.