CVE-2007-2719: Critical severity HP Systems Insight Manager vulnerability
Published May 16, 2007
·Updated
Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
Affected Software
3 affected components
HP Systems Insight Manager=4.2
HP Systems Insight Manager=5.0-sp4
HP Systems Insight Manager=5.0-sp5
Remediation
Patch Available
Event History
May 16, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2719?
CVE-2007-2719 is classified as a moderate severity vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2007-2719?
To fix CVE-2007-2719, update HP Systems Insight Manager to a version that addresses the session fixation vulnerability.
3
Which versions of HP Systems Insight Manager are affected by CVE-2007-2719?
CVE-2007-2719 affects HP Systems Insight Manager versions 4.2, 5.0 SP4, and 5.0 SP5.
4
What type of attack does CVE-2007-2719 facilitate?
CVE-2007-2719 facilitates session hijacking attacks, allowing remote attackers to take control of a user's web session.
5
Is CVE-2007-2719 exploitable remotely?
Yes, CVE-2007-2719 can be exploited remotely by attackers to hijack web sessions.