VulnerabilityModified
CVE-2011-2222
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
MEDIUM 4.3EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- novell/data synchronizer · novell/mobility pack
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009054Vendor Advisory
- http://www.securityfocus.com/bid/49069
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009054Vendor Advisory
- http://www.securityfocus.com/bid/49069
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.