WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-09-03T19:00:00Z
Updated: 2024-09-16T17:08:35.595Z
Reserved: 2010-04-26T00:00:00Z
Link: CVE-2010-1507
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-09-03T20:00:01.527
Modified: 2024-11-21T01:14:35.583
Link: CVE-2010-1507
Redhat
No data.