Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
| Software | From | Fixed in |
|---|---|---|
| hp / systems_insight_manager | 4.2 | 4.2.x |
| hp / systems_insight_manager | 5.0-sp5 | 5.0-sp5.x |
| hp / systems_insight_manager | 5.0-sp4 | 5.0-sp4.x |