Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2014-12-15T17:27:00
Updated: 2024-08-06T13:40:24.989Z
Reserved: 2014-12-12T00:00:00
Link: CVE-2014-9386
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-12-15T18:59:28.630
Modified: 2024-11-21T02:20:45.100
Link: CVE-2014-9386
Redhat
No data.