CVE Vulnerabilities

CVE-2007-2719

Improper Authentication

Published: May 16, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Systems_insight_manager Hp 4.2 (including) 4.2 (including)
Systems_insight_manager Hp 5.0-sp4 (including) 5.0-sp4 (including)
Systems_insight_manager Hp 5.0-sp5 (including) 5.0-sp5 (including)

Potential Mitigations

References