CVE-2013-2049Session Fixation in Redhat Cloudforms Management Engine

CWE-384Session Fixation6 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.2%
top 63.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 14

Description

Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hwwg-f5h3-wwv3: Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token2022-05-14
CVEList
CVE-2013-2049: Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token2018-05-01

💥Exploits & PoCs

1
Exploit-DB
D-Link DCS-931L - Arbitrary File Upload (Metasploit)2016-01-07

📋Vendor Advisories

1
Red Hat
2: static secret_token.rb value2013-11-13

💬Community

1
Bugzilla
CVE-2013-2049 CloudForms Management Engine 2: static secret_token.rb value2013-05-03
CVE-2013-2049 — Session Fixation in Redhat | cvebase