5
CVSSv2

CVE-2014-0999

Published: 02/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Sendio prior to 7.2.4 includes the session identifier in URLs in emails, which allows remote malicious users to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.

Vulnerable Product Search on Vulmon Subscribe to Product

sendio sendio

Exploits

1 Advisory Information Title: Sendio ESP Information Disclosure Vulnerability Advisory ID: CORE-2015-0010 Advisory URL: wwwcoresecuritycom/advisories/sendio-esp-information-disclosure-vulnerability Date published: 2015-05-22 Date of last update: 2015-05-22 Vendors contacted: Sendio Release mode: Coordinated release 2 Vulnerability Inf ...
Core Security Technologies Advisory - Sendio ESP (E-mail Security Platform) is a network appliance which provides anti-spam and anti-virus solutions for enterprises Two information disclosure issues were found affecting some versions of this software, and can lead to leakage of sensitive information such as user's session identifiers and/or user's ...