First published: Wed Aug 22 2012(Updated: )
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Email and Web Security | =5.0 | |
McAfee Email and Web Security | =5.5 | |
McAfee Email and Web Security | =5.6 | |
McAfee Email Gateway | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4583 has a medium severity rating due to the ability of remote authenticated users to access session tokens of other users.
To mitigate CVE-2012-4583, update to McAfee Email and Web Security version 5.5 Patch 6 or 5.6 Patch 3, or McAfee Email Gateway version 7.0 Patch 1.
CVE-2012-4583 affects McAfee Email and Web Security versions 5.0, 5.5, 5.6, and McAfee Email Gateway version 7.0.
CVE-2012-4583 allows remote authenticated users to hijack session tokens, potentially leading to unauthorized access.
Yes, CVE-2012-4583 is a documented vulnerability that was reported in 2012, requiring attention from affected users.