← Back

CVE-2009-4354

nvd nist
Published: Dec 17, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the "secure" flag for cookies in SSL sessions.

Affected (3)

1 product
Active! Mail
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Transware
Up to 2003
Version 1.422
Version 2.0

Related CWEs

References (8)

Timeline

No history available yet.