First published: Fri Sep 03 2010(Updated: )
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Suse Linux | =11 | |
Novell Webyast Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.