Lucene search

K
jvnJapan Vulnerability NotesJVN:60931933
HistoryNov 21, 2012 - 12:00 a.m.

JVN#60931933: BIGACE vulnerable to session fixation

2012-11-2100:00:00
Japan Vulnerability Notes
jvn.jp
15

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.006

Percentile

79.3%

BIGACE is a content management system (CMS). BIGACE contains a session fixation vulnerability.

Impact

A remote unauthenticated attacker may impersonate a registered user. As a result, information disclosure or alteration may be possible.

Solution

Update the Software
Apply the latest update according to the information provided by the developer.

Products Affected

  • BIGACE 2.7.7 and earlier

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.006

Percentile

79.3%

Related for JVN:60931933