Description
EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://seclists.org/bugtraq/2015/Oct/58
Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/133922/EMC-SourceOne-Email-Supervisor-XSS-Session-Hijacking.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033787
Scores
EPSS
0.0149
EPSS Percentile
81.3%
Details
Status
published
Products (1)
emc/sourceone_email_supervisor
< 7.1
Published
Oct 18, 2015
Tracked Since
Feb 18, 2026