Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zenworks_configuration_management | Novell | * | 11.2.3 (including) |
Zenworks_configuration_management | Novell | 10.2 (including) | 10.2 (including) |
Zenworks_configuration_management | Novell | 10.3 (including) | 10.3 (including) |
Zenworks_configuration_management | Novell | 10.3.1 (including) | 10.3.1 (including) |
Zenworks_configuration_management | Novell | 10.3.2 (including) | 10.3.2 (including) |
Zenworks_configuration_management | Novell | 10.3.3 (including) | 10.3.3 (including) |
Zenworks_configuration_management | Novell | 11 (including) | 11 (including) |
Zenworks_configuration_management | Novell | 11-sp1 (including) | 11-sp1 (including) |
Zenworks_configuration_management | Novell | 11.2 (including) | 11.2 (including) |