First published: Sat Jan 25 2020(Updated: )
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Nexpose | <5.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2012-6494.
The severity of CVE-2012-6494 is medium.
The affected software is Rapid7 Nexpose versions up to exclusive version 5.5.4.
CVE-2012-6494 is a session hijacking vulnerability in Rapid7 Nexpose before 5.5.4, allowing remote attackers to capture a user's session and gain unauthorized access.
To fix CVE-2012-6494, you should update Rapid7 Nexpose to version 5.5.4 or later.