CVE-2019-7215
 
Severity Score
6.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Progress Sitefinity 10.1.6536 no invalida las cookies de sesión al cerrar la sesión. En su lugar, intenta sobrescribir la cookie en el navegador, pero sigue siendo válida en el lado del servidor. Esto significa que la cookie se puede reutilizar para mantener el acceso a la cuenta, incluso si se cambian las credenciales y los permisos de la cuenta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-29 CVE Reserved
- 2019-06-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-613: Insufficient Session Expiration
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://knowledgebase.progress.com/#sort=relevancy&f:%40objecttypelabel=%5BProduct%20Alert%5D | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 7.0 < 7.0.5143 Search vendor "Progress" for product "Sitefinity" and version " >= 7.0 < 7.0.5143" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 7.1 < 7.1.5243 Search vendor "Progress" for product "Sitefinity" and version " >= 7.1 < 7.1.5243" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 7.2 < 7.2.5353 Search vendor "Progress" for product "Sitefinity" and version " >= 7.2 < 7.2.5353" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 7.3 < 7.3.5693 Search vendor "Progress" for product "Sitefinity" and version " >= 7.3 < 7.3.5693" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 8.0 < 8.0.5773 Search vendor "Progress" for product "Sitefinity" and version " >= 8.0 < 8.0.5773" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 8.1 < 8.1.5863 Search vendor "Progress" for product "Sitefinity" and version " >= 8.1 < 8.1.5863" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 8.2 < 8.2.5973 Search vendor "Progress" for product "Sitefinity" and version " >= 8.2 < 8.2.5973" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 9.0 < 9.0.6063 Search vendor "Progress" for product "Sitefinity" and version " >= 9.0 < 9.0.6063" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 9.1 < 9.1.6183 Search vendor "Progress" for product "Sitefinity" and version " >= 9.1 < 9.1.6183" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 9.2 < 9.2.6274 Search vendor "Progress" for product "Sitefinity" and version " >= 9.2 < 9.2.6274" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 10.0 < 10.0.6429 Search vendor "Progress" for product "Sitefinity" and version " >= 10.0 < 10.0.6429" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 10.1 <= 10.1.6540 Search vendor "Progress" for product "Sitefinity" and version " >= 10.1 <= 10.1.6540" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 10.2 < 10.2.6649 Search vendor "Progress" for product "Sitefinity" and version " >= 10.2 < 10.2.6649" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 11.0 < 11.0.6736 Search vendor "Progress" for product "Sitefinity" and version " >= 11.0 < 11.0.6736" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 11.1 < 11.1.6826 Search vendor "Progress" for product "Sitefinity" and version " >= 11.1 < 11.1.6826" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 11.2 < 11.2.6929 Search vendor "Progress" for product "Sitefinity" and version " >= 11.2 < 11.2.6929" | - |
Affected
|