Vulnerability Description
The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Transware | Active\! Mail | <= 2003 |
References
- http://jvn.jp/en/jp/JVN85821104/index.html
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000076.html
- http://secunia.com/advisories/37602Vendor Advisory
- http://www.transware.co.jp/support_am/security/vulnerability3.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54751
- http://jvn.jp/en/jp/JVN85821104/index.html
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000076.html
- http://secunia.com/advisories/37602Vendor Advisory
- http://www.transware.co.jp/support_am/security/vulnerability3.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54751
FAQ
What is CVE-2009-4353?
CVE-2009-4353 is a vulnerability with a CVSS score of 5.8 (MEDIUM). The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows rem...
How severe is CVE-2009-4353?
CVE-2009-4353 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4353?
Check the references section above for vendor advisories and patch information. Affected products include: Transware Active\! Mail.