Lucene search

K
cveRedhatCVE-2012-2735
HistorySep 28, 2012 - 5:55 p.m.

CVE-2012-2735

2012-09-2817:55:01
redhat
web.nvd.nist.gov
35
cve
2012
2735
session fixation
cumin
red hat
enterprise messaging
realtime
grid
mrg 2.0
remote hijacking

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

56.5%

Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.

Affected configurations

Nvd
Node
trevor_mckaycuminRange0.1.5192-4
OR
trevor_mckaycuminMatch0.1.3160-1
OR
trevor_mckaycuminMatch0.1.4369-1
OR
trevor_mckaycuminMatch0.1.4410-2
OR
trevor_mckaycuminMatch0.1.4494-1
OR
trevor_mckaycuminMatch0.1.4794-1
OR
trevor_mckaycuminMatch0.1.4916-1
OR
trevor_mckaycuminMatch0.1.5033-1
OR
trevor_mckaycuminMatch0.1.5037-1
OR
trevor_mckaycuminMatch0.1.5054-1
OR
trevor_mckaycuminMatch0.1.5068-1
OR
trevor_mckaycuminMatch0.1.5092-1
OR
trevor_mckaycuminMatch0.1.5098-2
OR
trevor_mckaycuminMatch0.1.5105-1
OR
trevor_mckaycuminMatch0.1.5137-1
OR
trevor_mckaycuminMatch0.1.5137-2
OR
trevor_mckaycuminMatch0.1.5137-3
OR
trevor_mckaycuminMatch0.1.5137-4
OR
trevor_mckaycuminMatch0.1.5137-5
OR
trevor_mckaycuminMatch0.1.5192-1
OR
redhatenterprise_mrgMatch2.0
VendorProductVersionCPE
trevor_mckaycumin*cpe:2.3:a:trevor_mckay:cumin:*:*:*:*:*:*:*:*
trevor_mckaycumin0.1.3160-1cpe:2.3:a:trevor_mckay:cumin:0.1.3160-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.4369-1cpe:2.3:a:trevor_mckay:cumin:0.1.4369-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.4410-2cpe:2.3:a:trevor_mckay:cumin:0.1.4410-2:*:*:*:*:*:*:*
trevor_mckaycumin0.1.4494-1cpe:2.3:a:trevor_mckay:cumin:0.1.4494-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.4794-1cpe:2.3:a:trevor_mckay:cumin:0.1.4794-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.4916-1cpe:2.3:a:trevor_mckay:cumin:0.1.4916-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.5033-1cpe:2.3:a:trevor_mckay:cumin:0.1.5033-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.5037-1cpe:2.3:a:trevor_mckay:cumin:0.1.5037-1:*:*:*:*:*:*:*
trevor_mckaycumin0.1.5054-1cpe:2.3:a:trevor_mckay:cumin:0.1.5054-1:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

56.5%