Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
BID:66982
Info
Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
| Bugtraq ID: | 66982 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1984 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2014 12:00AM |
| Updated: | Apr 18 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Cybozu Remote Service Manager 3.1 Cybozu Remote Service Manager 3.0 Cybozu Remote Service Manager 2.3 Cybozu Remote Service Manager 2.0 |
| Not Vulnerable: |
Cybozu Remote Service Manager 3.1.1 |
Discussion
Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
Cybozu Remote Service Manager is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
The following versions are vulnerable:
Cybozu Remote Service Manager 2.3.0 and earlier
Cybozu Remote Service Manager 3.1.0 and earlier
Cybozu Remote Service Manager is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
The following versions are vulnerable:
Cybozu Remote Service Manager 2.3.0 and earlier
Cybozu Remote Service Manager 3.1.0 and earlier
Exploit / POC
Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cybozu Remote Service Manager CVE-2014-1984 Session Fixation Vulnerability
References:
References: