CVE-2012-4583: Infoleak
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4583?
CVE-2012-4583 has a medium severity rating due to the ability of remote authenticated users to access session tokens of other users.
How do I fix CVE-2012-4583?
To mitigate CVE-2012-4583, update to McAfee Email and Web Security version 5.5 Patch 6 or 5.6 Patch 3, or McAfee Email Gateway version 7.0 Patch 1.
Who is affected by CVE-2012-4583?
CVE-2012-4583 affects McAfee Email and Web Security versions 5.0, 5.5, 5.6, and McAfee Email Gateway version 7.0.
What type of attack does CVE-2012-4583 allow?
CVE-2012-4583 allows remote authenticated users to hijack session tokens, potentially leading to unauthorized access.
Is CVE-2012-4583 a known vulnerability?
Yes, CVE-2012-4583 is a documented vulnerability that was reported in 2012, requiring attention from affected users.