CVE-2008-6569: Medium severity Cybozu Garoon vulnerability
Published Mar 31, 2009
·Updated
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
Affected Software
11 affected components
Cybozu Garoon=2.1.0
Cybozu Garoon=2.0.2
Cybozu Garoon=2.0.4
Cybozu Garoon=2.0.6
Cybozu Garoon=2.1.3
Cybozu Garoon=2.0.5
Cybozu Garoon=2.0.3
Cybozu Garoon=2.1.1
Cybozu Garoon=2.0.1
Cybozu Garoon=2.1.2
Cybozu Garoon=2.0.0
Event History
Mar 31, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6569?
CVE-2008-6569 is classified as a high severity vulnerability due to its potential to allow session hijacking.
2
How do I fix CVE-2008-6569?
To fix CVE-2008-6569, upgrade Cybozu Garoon to version 2.1.4 or later, which addresses the session fixation issue.
3
What products are affected by CVE-2008-6569?
CVE-2008-6569 affects Cybozu Garoon versions 2.0.0 through 2.1.3.
4
What type of vulnerability is CVE-2008-6569?
CVE-2008-6569 is a session fixation vulnerability that allows attackers to hijack user sessions.
5
Can CVE-2008-6569 lead to data breaches?
Yes, CVE-2008-6569 can potentially lead to unauthorized access to sensitive user data.