7.5
CVE-2024-2493
- EPSS 0.04%
- Veröffentlicht 23.04.2024 06:15:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle hirt@hitachi.co.jp
- CVE-Watchlists
- Unerledigt
Session Hijacking Vulnerability in Hitachi Ops Center Analyzer
Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.1-00.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerhitachi
≫
Produkt
alaxala
Default Statusunknown
Version
10.0.0.00
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| hirt@hitachi.co.jp | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.