CVE-2005-2185: High severity EMC Eroom vulnerability
Published Jul 10, 2005
·Updated
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.
Affected Software
8 affected components
EMC Eroom=6.0.6
EMC Eroom=6.0.1
EMC Eroom=6.0.5
EMC Eroom=6.0.7
EMC Eroom=6.0
EMC Eroom=6.0.4
EMC Eroom=6.0.2
EMC Eroom=6.0.3
Event History
Jul 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2185?
CVE-2005-2185 is considered a high severity vulnerability due to its potential for replay attacks.
2
How do I fix CVE-2005-2185?
To fix CVE-2005-2185, ensure that cookies set by eRoom include expiration parameters.
3
Which versions of eRoom are affected by CVE-2005-2185?
CVE-2005-2185 affects eRoom versions 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.7.
4
What type of attack can be executed due to CVE-2005-2185?
CVE-2005-2185 allows remote attackers to conduct replay attacks by capturing unexpired cookies.
5
Who is the vendor associated with CVE-2005-2185?
The vendor associated with CVE-2005-2185 is EMC, which developed the eRoom application.