Vulnerabilities > CVE-2014-2509 - Session Fixation vulnerability in EMC Smarts Network Configuration Manager 9.1/9.2

047910
CVSS 5.4 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie. Per: http://cwe.mitre.org/data/definitions/384.html "CWE-384: Session Fixation"

Vulnerable Configurations

Part Description Count
Application
Emc
2