First published: Wed Dec 31 2003(Updated: )
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netegrity Policy Server | ||
Netegrity Policy Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1312 is considered a high severity vulnerability due to the potential for session ID exposure.
To fix CVE-2003-1312, you should upgrade to a patched version of Netegrity SiteMinder that addresses this vulnerability.
Any users or organizations utilizing Netegrity SiteMinder without the appropriate updates are affected by CVE-2003-1312.
CVE-2003-1312 can be exploited to intercept session ID information, allowing attackers to impersonate users.
CVE-2003-1312 allows remote attacks by exposing the SMSESSION parameter in URLs, which can be captured through various methods such as sniffing or Referer logs.