|
[Japanese]
|
JVNDB-2004-000588
|
SSL-VPN products vulnerable to cookie theft
|
When using an SSL-VPN product, if a user selects a mode in which the user can log in with the username and password without using the SSL client authentication, a session hijacking could be conducted.
|
Base Metrics:
2.1 (Low)
[IPA Score]
- Access Vector: Local
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
|
Yokogawa Electric Corporation
- SecureTicket before ver.4.0.b
|
|
An attacker may be able to intercept a session ID stored in a cookie and hijack a login user's session.
|
|
Yokogawa Electric Corporation
|
|
- CVE-2004-0462
|
- JVN : JVN#67B82FA3
- National Vulnerability Database (NVD) : CVE-2004-0462
- US-CERT Vulnerability Note : VU#546483
- ISS X-Force Database : 17702
|
[2008/05/21]
Web page published
|