Emc vplex GeoSynchrony Session Fixation Vulnerability (CVE-2014-0635)
Release date:
Updated on:
Affected Systems:
Emc vplex GeoSynchrony 4.0-5.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66514
CVE (CAN) ID: CVE-2014-0635
Emc vplex GeoSynchrony is a virtual machine data storage software.
VPLEX GeoSynchrony 4.0-5.2.1 has a session fixation vulnerability. After successful exploitation, remote attackers can hijack arbitrary sessions and access affected applications without authorization.
<* Source: vendor
Link: http://www.securityfocus.com/archive/1/531639
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
EMC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.emc.com/products-solutions/index.htm