HTTP: CA 2E Web Option Unauthenticated Privilege Escalation

There exists a vulnerability in CA 2E Web Option. Successful Exploitation can lead to unauthenticated privilege escalation via a predictable session token.

Extended Description

CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.

Affected Products

Ca 2e_web_option

References

CVE: CVE-2014-1219

Short Name
HTTP:CA-SSNID-PE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
2E CA CVE-2014-1219 Escalation Option Privilege Unauthenticated Web
Release Date
04/18/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Ca

CVSS Score

5.1

Found a potential security threat?