First published: Fri May 03 2002(Updated: )
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lucent Vitalevent | =8.0 | |
Lucent VitalSuite | =8.0 | |
Lucent VitalSuite | =8.2 | |
Lucent Vitalnet | =8.0 | |
Lucent VitalSuite | =8.1 | |
Lucent Vitalanalysis | =8.0 | |
Lucent Vitalhelp | =8.2 | |
Lucent Vitalanalysis | =8.2 | |
Lucent Vitalnet | =8.1 | |
Lucent Vitalhelp | =8.0 | |
Lucent Vitalevent | =8.2 | |
Lucent Vitalhelp | =8.1 | |
Lucent Vitalanalysis | =8.1 | |
Lucent Vitalnet | =8.2 | |
Lucent Vitalevent | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.