Beveiligingsadvies

CVE-2003-1312

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2006-12-15 19:00:00
Laatst bijgewerkt 2024-08-08 02:19:46
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.