CVE-2012-4581 Information
Feb 14, 2021
cve
Description
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3 and McAfee Email Gateway (MEG) 7.0 before Patch 1 does not disable the server-side session token upon the closing of the Management Console/Dashboard which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt related to a \Logout Failure\ issue.
Reference
https://kc.mcafee.com/corporate/index?page=content&id=SB10020
Share on: