CVE-2002-0258
Last modified
CVE-2002-0258 is a vulnerability of currently unknown severity. Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icewarp | Web Mail | All versions |
| Merak | Mail Server | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0258?
How severe is CVE-2002-0258?
How do I fix CVE-2002-0258?
Are you affected by CVE-2002-0258?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
