6.8
CVSSv2

CVE-2012-4581

Published: 22/08/2012 Updated: 22/08/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

McAfee Email and Web Security (EWS) 5.x prior to 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote malicious users to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a "Logout Failure" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee email and web security 5.6

mcafee email and web security 5.0

mcafee email and web security 5.5

mcafee email gateway 7.0