Vulnerability Description
Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Systems Insight Manager | 4.2 |
Related Weaknesses (CWE)
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&obje
- http://osvdb.org/36061
- http://secunia.com/advisories/25275Vendor Advisory
- http://www.acrossecurity.com/aspr/ASPR-2007-05-14-1-PUB.txtPatch
- http://www.securityfocus.com/archive/1/468974/100/0/threaded
- http://www.securityfocus.com/bid/23988
- http://www.securitytracker.com/id?1018062
- http://www.vupen.com/english/advisories/2007/1823
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34303
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&obje
- http://osvdb.org/36061
- http://secunia.com/advisories/25275Vendor Advisory
- http://www.acrossecurity.com/aspr/ASPR-2007-05-14-1-PUB.txtPatch
- http://www.securityfocus.com/archive/1/468974/100/0/threaded
- http://www.securityfocus.com/bid/23988
FAQ
What is CVE-2007-2719?
CVE-2007-2719 is a vulnerability with a CVSS score of 10.0 (HIGH). Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
How severe is CVE-2007-2719?
CVE-2007-2719 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2719?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Systems Insight Manager.