Lucene search

K
cvelistMitreCVELIST:CVE-2012-4581
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4581

2022-10-0316:15:34
mitre
www.cve.org
cve-2012-4581
session hijacking
session token
security patch
remote attackers
management console
logout failure

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.8%

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a β€œLogout Failure” issue.

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.8%

Related for CVELIST:CVE-2012-4581