First published: Tue Aug 09 2011(Updated: )
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Mobility Pack | =1.1 | |
Novell Data Synchronizer | =1.1.2 | |
Novell Data Synchronizer | =1.1.0 | |
Novell Data Synchronizer | =1.1.1 | |
Novell Mobility Pack | =1.1.2 | |
Novell Data Synchronizer | =1.0.0 | |
Novell Mobility Pack | =1.0 | |
Novell Mobility Pack | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2222 has a high severity rating due to its potential to allow remote attackers to hijack web sessions.
To fix CVE-2011-2222, upgrade to a version of Novell Data Synchronizer or Mobility Pack that is patched against this vulnerability.
CVE-2011-2222 affects Novell Mobility Pack versions 1.0 to 1.1.2 and Novell Data Synchronizer versions 1.0.0 to 1.1.2.
CVE-2011-2222 is a session fixation vulnerability that can be exploited by remote attackers.
Exploitation of CVE-2011-2222 may lead to unauthorized access to user sessions, compromising user accounts.