CVE-2009-4354 describes a session hijacking vulnerability in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, where the session ID in a session cookie is not properly secured, likely due to an issue with the "secure" flag in SSL sessions. This vulnerability has a CVSS score of 5.8, indicating a medium severity, and allows unauthenticated remote attackers to compromise confidentiality and integrity with moderate attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2003CPE matchmatch criteria | cpe:2.3:a:transware:active\!_mail:*:*:*:*:*:*:*:* | ||
1.422CPE matchmatch criteria | cpe:2.3:a:transware:active\!_mail:1.422:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:transware:active\!_mail:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.