CVE Vulnerabilities

CVE-2014-9386

Published: Dec 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

Affected Software

Name Vendor Start Version End Version
Zenoss_core Zenoss * 4.2.5 (including)
Zenoss_core Zenoss 2.4.0 (including) 2.4.0 (including)
Zenoss_core Zenoss 2.4.5 (including) 2.4.5 (including)
Zenoss_core Zenoss 2.5.0 (including) 2.5.0 (including)
Zenoss_core Zenoss 2.5.1 (including) 2.5.1 (including)
Zenoss_core Zenoss 2.5.2 (including) 2.5.2 (including)
Zenoss_core Zenoss 3.0.0 (including) 3.0.0 (including)
Zenoss_core Zenoss 3.0.1 (including) 3.0.1 (including)
Zenoss_core Zenoss 3.0.2 (including) 3.0.2 (including)
Zenoss_core Zenoss 3.0.3 (including) 3.0.3 (including)
Zenoss_core Zenoss 3.1.0 (including) 3.1.0 (including)
Zenoss_core Zenoss 3.2.0 (including) 3.2.0 (including)
Zenoss_core Zenoss 3.2.1 (including) 3.2.1 (including)
Zenoss_core Zenoss 4.2.0 (including) 4.2.0 (including)
Zenoss_core Zenoss 4.2.3 (including) 4.2.3 (including)
Zenoss_core Zenoss 4.2.4 (including) 4.2.4 (including)

References