Session Hijacking Vulnerability in McAfee Email and Web Security (EWS) and McAfee Email Gateway (MEG)

Session Hijacking Vulnerability in McAfee Email and Web Security (EWS) and McAfee Email Gateway (MEG)

CVE-2012-4581 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a "Logout Failure" issue.

Learn more about our Web App Pen Testing.