CVE-2013-6347: Medium severity Novell ZENworks Configuration Management vulnerability
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Novell ZENworks Configuration Management (ZCM)to a version that resolves this vulnerability.Fixed in 11.2.4
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6347?
CVE-2013-6347 has a high severity rating due to its potential to allow remote attackers to hijack web sessions.
How do I fix CVE-2013-6347?
To fix CVE-2013-6347, you should upgrade your Novell ZENworks Configuration Management to version 11.2.4 or later.
Which versions of Novell ZENworks Configuration Management are affected by CVE-2013-6347?
CVE-2013-6347 affects Novell ZENworks Configuration Management versions prior to 11.2.4, including 10.2, 10.3, and earlier 11.x versions.
What type of vulnerability is CVE-2013-6347?
CVE-2013-6347 is classified as a session fixation vulnerability.
Can CVE-2013-6347 be exploited remotely?
Yes, CVE-2013-6347 can be exploited remotely, allowing attackers to hijack active web sessions.