4

CVE-2010-2149

Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fujitsu ≫ E-pares Version l01
Fujitsu ≫ E-pares Version l03
Fujitsu ≫ E-pares Version l10
Fujitsu ≫ E-pares Version l20
Fujitsu ≫ E-pares Version l30
Fujitsu ≫ E-pares Version v01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.748
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://jvn.jp/en/jp/JVN36925871/index.html
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000023.html
http://secunia.com/advisories/40029
Vendor Advisory
http://software.fujitsu.com/jp/security/vulnerabilities/jvn-36925871-58439007-82465391.html
Vendor Advisory
http://www.securityfocus.com/bid/40513