« Volver al listado

CVE-2009-4354

Estado: ModificadaMedia (5.8)—

TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the "secure" flag for cookies in SSL sessions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4354",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-12-17T18:30:00.280",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN36207497/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000077.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.transware.co.jp/support_am/security/vulnerability1.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54752",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN36207497/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000077.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.transware.co.jp/support_am/security/vulnerability1.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54752",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the \"secure\" flag for cookies in SSL sessions."
    },
    {
      "lang": "es",
      "value": "Transware Active! mail 2003 build 2003.0139.0871 y anteriores no asegura correctamente el identificador de sesión en una cookie de sesión, lo que permite secuestrar sesiones web a atacantes remotos. Una vulberabilidad probablemente relacionada con el flag \"secure\" para las \"cookies\" en las sesiones SSL."
    }
  ],
  "lastModified": "2026-06-16T23:13:30.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:transware:active\\!_mail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0CFFAA1-1385-46DD-A3EA-E0F3876AC997",
              "versionEndIncluding": "2003"
            },
            {
              "criteria": "cpe:2.3:a:transware:active\\!_mail:1.422:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "981485E0-5080-4F32-B50B-B5695645C90C"
            },
            {
              "criteria": "cpe:2.3:a:transware:active\\!_mail:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "449AD2C6-08F0-4B92-8F2C-6D919B68E850"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}