CVE-2004-1478: High severity Hitachi Cosminexus Enterprise vulnerability
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1478?
CVE-2004-1478 is classified as a high severity vulnerability due to its potential for allowing session fixation attacks.
How do I fix CVE-2004-1478?
To fix CVE-2004-1478, update JRun or ColdFusion to the latest version that addresses this vulnerability.
What systems are affected by CVE-2004-1478?
CVE-2004-1478 affects specific versions of Macromedia JRun and ColdFusion, as well as certain Hitachi Cosminexus Enterprise versions.
What type of attack does CVE-2004-1478 enable?
CVE-2004-1478 enables session fixation attacks that allow attackers to hijack users' HTTP sessions.
Is CVE-2004-1478 still relevant today?
Despite its age, CVE-2004-1478 remains relevant for environments using outdated software versions that are vulnerable to this type of attack.