Session ID Exposure in Netegrity SiteMinder's SMSESSION Parameter

Session ID Exposure in Netegrity SiteMinder's SMSESSION Parameter

CVE-2003-1312 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.

Learn more about our Web Application Penetration Testing UK.