5
CVSSv2

CVE-2010-1507

Published: 03/09/2010 Updated: 06/09/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote malicious users to spoof session cookies by leveraging knowledge of this key.

Vulnerable Product Search on Vulmon Subscribe to Product

novell suse_linux 11