Insecure Session Cookie Generation in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x

Insecure Session Cookie Generation in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x

CVE-2015-0544 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

Learn more about our Web Application Penetration Testing UK.