Back to search
CVE-2010-1507
Published: Sep 3, 2010
Modified: Sep 16, 2024
PUBLISHED
Description
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.novell.com/show_bug.cgi?id=591345
x_refsource_CONFIRM
http://support.novell.com/security/cve/CVE-2010-1507.html
x_refsource_CONFIRM
42128
vdb-entry
x_refsource_BID
SUSE-SR:2010:014
vendor-advisory
x_refsource_SUSE
https://bugzilla.novell.com/show_bug.cgi?id=598834
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now