CVE Vulnerabilities

CVE-2014-9386

Published: Dec 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

Affected Software

NameVendorStart VersionEnd Version
Zenoss_coreZenoss*4.2.5 (including)
Zenoss_coreZenoss2.4.0 (including)2.4.0 (including)
Zenoss_coreZenoss2.4.5 (including)2.4.5 (including)
Zenoss_coreZenoss2.5.0 (including)2.5.0 (including)
Zenoss_coreZenoss2.5.1 (including)2.5.1 (including)
Zenoss_coreZenoss2.5.2 (including)2.5.2 (including)
Zenoss_coreZenoss3.0.0 (including)3.0.0 (including)
Zenoss_coreZenoss3.0.1 (including)3.0.1 (including)
Zenoss_coreZenoss3.0.2 (including)3.0.2 (including)
Zenoss_coreZenoss3.0.3 (including)3.0.3 (including)
Zenoss_coreZenoss3.1.0 (including)3.1.0 (including)
Zenoss_coreZenoss3.2.0 (including)3.2.0 (including)
Zenoss_coreZenoss3.2.1 (including)3.2.1 (including)
Zenoss_coreZenoss4.2.0 (including)4.2.0 (including)
Zenoss_coreZenoss4.2.3 (including)4.2.3 (including)
Zenoss_coreZenoss4.2.4 (including)4.2.4 (including)

References