VulnerabilityModified
CVE-2008-6569
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
MEDIUM 6.8EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cybozu/garoon
- Source
- cve@mitre.org
References
- http://cybozu.co.jp/products/dl/notice/detail/0021.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN18700809/index.htmlVendor Advisory
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000034.htmlVendor Advisory
- http://osvdb.org/46564
- http://secunia.com/advisories/30871Vendor Advisory
- http://www.lac.co.jp/info/advisory/98.html
- http://www.securityfocus.com/bid/29981
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43427
- http://cybozu.co.jp/products/dl/notice/detail/0021.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN18700809/index.htmlVendor Advisory
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000034.htmlVendor Advisory
- http://osvdb.org/46564
- http://secunia.com/advisories/30871Vendor Advisory
- http://www.lac.co.jp/info/advisory/98.html
- http://www.securityfocus.com/bid/29981
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43427
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.