e-Pares Session Fixation Vulnerability
BID:40513
Info
e-Pares Session Fixation Vulnerability
| Bugtraq ID: | 40513 |
| Class: | Design Error |
| CVE: |
CVE-2010-2149 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Yamaya Akira |
| Vulnerable: |
Fujitsu e-Pares L30 Fujitsu e-Pares L20 Fujitsu e-Pares L10 Fujitsu e-Pares L03 Fujitsu e-Pares L01 Fujitsu e-Pares 01 |
| Not Vulnerable: | |
Discussion
e-Pares Session Fixation Vulnerability
e-Pares is prone to a session-fixation vulnerability.
Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the affected application.
e-Pares 01, L01, L03, L10, L20, and L30 are vulnerable; other versions may be affected.
e-Pares is prone to a session-fixation vulnerability.
Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the affected application.
e-Pares 01, L01, L03, L10, L20, and L30 are vulnerable; other versions may be affected.
Exploit / POC
e-Pares Session Fixation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
e-Pares Session Fixation Vulnerability
Solution:
Reports indicate vendor updates are available; this has not been confirmed. Contact the vendor for more information.
Solution:
Reports indicate vendor updates are available; this has not been confirmed. Contact the vendor for more information.
References
e-Pares Session Fixation Vulnerability
References:
References:
- e-Pares - Homepage (Fujitsu)
- e-Pares Session fixation vulnerability in (Yamaya Akira)