First published: Fri Oct 12 2001(Updated: )
Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IPSWITCH IMail | =6.0.6 | |
IPSWITCH IMail | =6.0.2 | |
IPSWITCH IMail | =7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1284 is considered a high severity vulnerability due to its potential for session hijacking.
To fix CVE-2001-1284, upgrade to a version of Ipswitch IMail that is not affected, specifically versions later than 7.0.4.
CVE-2001-1284 affects Ipswitch IMail versions 6.0.2, 6.0.6, and 7.0.4 and earlier.
CVE-2001-1284 exposes users to session hijacking attacks that allow remote attackers to impersonate legitimate users.
There are no known effective workarounds for CVE-2001-1284; upgrading to a patched version is recommended.