CVE-2007-2719Improper Authentication in HP Systems Insight Manager

Severity
10.0CRITICALNVD
EPSS
7.5%
top 8.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Latest updateMay 1

Description

Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fwpj-2768-6hfr: Session fixation vulnerability in HP Systems Insight Manager (SIM) 42022-05-01
CVEList
CVE-2007-2719: Session fixation vulnerability in HP Systems Insight Manager (SIM) 42007-05-16
CVE-2007-2719 — Improper Authentication in HP | cvebase