Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_data_loss_prevention | Mcafee | * | 9.3.4.1.5 (excluding) |
Network_security_manager | Mcafee | * | 8.2.7.42.2 (excluding) |
Such a scenario is commonly observed when: