The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Metrics
Affected Vendors & Products
Fixes
Solution
Update MailGates V6.0 to version 6.1.7.040 or later. Update MailAudit V6.0 to version 6.1.7.040 or later.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Oct 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | CWE-732 |

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:41:04.608Z
Reserved: 2024-07-15T02:57:13.364Z
Link: CVE-2024-6739

Updated: 2024-08-01T21:41:04.608Z

Status : Modified
Published: 2024-07-15T04:15:02.073
Modified: 2024-11-21T09:50:13.223
Link: CVE-2024-6739

No data.

No data.