Vulnerabilities > CVE-2014-9386 - Unspecified vulnerability in Zenoss Core
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
Vulnerable Configurations
Statements
contributor | Zenoss |
lastmodified | 2016-03-21 |
organization | Zenoss |
statement | Addressed in versions 5.0, 4.2.5.SP273, and 4.2.4.SP854 |