CVE-2010-1507

SUSE Linux Enterprise 11 - Session Cookie Spoofing via Fixed Secret Key

Title source: llm
STIX 2.1

Description

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.

References (5)

Core 5
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=591345
Vendor Advisory x_refsource_confirm
http://support.novell.com/security/cve/CVE-2010-1507.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/42128
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=598834

Scores

EPSS 0.0014
EPSS Percentile 34.2%

Details

CWE
CWE-255
Status published
Products (1)
novell/suse_linux 11
Published Sep 03, 2010
Tracked Since Feb 18, 2026