First published: Fri May 03 2013(Updated: )
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms Management Engine | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2049 is a vulnerability in Red Hat CloudForms 2 Management Engine (CFME) that allows remote attackers to conduct session tampering attacks.
CVE-2013-2049 affects Red Hat CloudForms Management Engine version 2.0.
CVE-2013-2049 has a severity rating of 7.5, which is considered high.
Remote attackers can exploit CVE-2013-2049 by leveraging the use of a static secret_token.rb secret to conduct session tampering attacks.
Yes, there is a fix available for CVE-2013-2049. It is recommended to update to a patched version of Red Hat CloudForms Management Engine.