CVE-2012-2735
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2012
Last modified:
11/04/2025
Description
Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.
Impact
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trevor_mckay:cumin:*:*:*:*:*:*:*:* | 0.1.5192-4 (including) | |
| cpe:2.3:a:trevor_mckay:cumin:0.1.3160-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.4369-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.4410-2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.4494-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.4794-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.4916-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5033-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5037-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5054-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5068-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5092-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5098-2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5105-1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trevor_mckay:cumin:0.1.5137-1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151
- http://rhn.redhat.com/errata/RHSA-2012-1278.html
- http://rhn.redhat.com/errata/RHSA-2012-1281.html
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78776
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151
- http://rhn.redhat.com/errata/RHSA-2012-1278.html
- http://rhn.redhat.com/errata/RHSA-2012-1281.html
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78776



