Total vulnerabilities in the database
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Software | From | Fixed in |
---|---|---|
hitachi / cosminexus_enterprise | 01_01_1 | 01_01_1.x |
hitachi / cosminexus_enterprise | 01_02_2 | 01_02_2.x |
macromedia / jrun | 3.1 | 3.1.x |
macromedia / jrun | 3.0 | 3.0.x |
macromedia / coldfusion | 6.1 | 6.1.x |
macromedia / coldfusion | 6.0 | 6.0.x |
hitachi / cosminexus_server | web_01-01_2 | web_01-01_2.x |
hitachi / cosminexus_server | web_01-01_1 | web_01-01_1.x |
macromedia / jrun | 4.0 | 4.0.x |