RULE(RULE ID:333608)

Rule General Information
Release Date: 2021-06-01
Rule Name: Seeyon OA getSessionList.jsp Session Disclosure Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Seeyon OA collaborative management platform is a collaborative management software for medium and large enterprises, Seeyon OA getSessionList.jsp page has a Session leak vulnerability, which allows attackers to construct elaborate requests, echo the user's Session value, and then log in to any user. Perform unauthorized operations.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.