CVSS2
Attack Vector
LOCAL
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:H/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
34.3%
Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-3359 for the base64-encoded storage of the user and password in a cookie.
Vendor | Product | Version | CPE |
---|---|---|---|
redhat | conga | * | cpe:2.3:a:redhat:conga:*:*:*:*:*:*:*:* |
redhat | enterprise_linux | 5 | cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:* |