CVE-2013-6994: Medium severity OpenText Exceed OnDemand vulnerability
Published May 19, 2014
·Updated
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
Affected Software
1 affected component
OpenText Exceed OnDemand=8.0
Event History
May 19, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6994?
CVE-2013-6994 has been classified as high severity due to potential session fixation attacks.
2
How do I fix CVE-2013-6994?
To fix CVE-2013-6994, ensure your deployment of OpenText Exceed OnDemand is updated to the latest version with secure session handling.
3
What vulnerability does CVE-2013-6994 expose?
CVE-2013-6994 exposes OpenText Exceed OnDemand to session fixation attacks through the transmission of session IDs in cleartext.
4
Which versions of OpenText Exceed OnDemand are affected by CVE-2013-6994?
CVE-2013-6994 specifically affects OpenText Exceed OnDemand version 8.0.
5
How can attackers exploit CVE-2013-6994?
Attackers can exploit CVE-2013-6994 by sniffing the network traffic to capture session IDs, leading to unauthorized access.