{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T15:17:02.372","vulnerabilities":[{"cve":{"id":"CVE-2012-2735","sourceIdentifier":"secalert@redhat.com","published":"2012-09-28T17:55:01.070","lastModified":"2026-04-29T01:13:23.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie."},{"lang":"es","value":"Vulnerabilidad de fijación de sesión en Cumin antes de v0.1.5444, tal y como se usa en Red Hat Enterprise Messaging, Realtime, y Grid (MRG) v2.0 permite a atacantes remotos secuestrar sesiones web a través de una cookie de sesión modificada a mano."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:*:*:*:*:*:*:*:*","versionEndIncluding":"0.1.5192-4","matchCriteriaId":"EB8CE3E6-C78F-4363-B731-A7981046EE5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.3160-1:*:*:*:*:*:*:*","matchCriteriaId":"B33C6617-24FB-4C96-A786-D26B074B0569"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.4369-1:*:*:*:*:*:*:*","matchCriteriaId":"D6CF3F68-713E-48E8-8D37-4AE443AF87FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.4410-2:*:*:*:*:*:*:*","matchCriteriaId":"8BDF4FB8-5ECF-4A2F-8066-8C362574B55F"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.4494-1:*:*:*:*:*:*:*","matchCriteriaId":"6ADC326A-3CE8-4710-870B-BF540CCB4A5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.4794-1:*:*:*:*:*:*:*","matchCriteriaId":"FFB4776E-178C-4488-9C98-98859576E343"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.4916-1:*:*:*:*:*:*:*","matchCriteriaId":"77B6E427-B880-48EB-8139-2F54381539BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5033-1:*:*:*:*:*:*:*","matchCriteriaId":"9EABF881-94BA-4E76-8EDB-29A4DB7F68B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5037-1:*:*:*:*:*:*:*","matchCriteriaId":"476B4482-38CB-46FB-B05D-CBBCDA87B739"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5054-1:*:*:*:*:*:*:*","matchCriteriaId":"F49E39C4-D9D4-44D0-9F24-2DB3EB1E4457"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5068-1:*:*:*:*:*:*:*","matchCriteriaId":"75A69413-E0B0-4528-8C42-898866BD3B9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5092-1:*:*:*:*:*:*:*","matchCriteriaId":"00B69A8C-A652-4CBB-80B1-171630C7420E"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5098-2:*:*:*:*:*:*:*","matchCriteriaId":"11E7AFB1-7864-47D4-AD75-9B9950BE7BBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5105-1:*:*:*:*:*:*:*","matchCriteriaId":"B9C553FD-1ED7-436A-B4A7-309C79CB7793"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5137-1:*:*:*:*:*:*:*","matchCriteriaId":"4CBBA885-F992-464D-9DF4-047F824FC02B"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5137-2:*:*:*:*:*:*:*","matchCriteriaId":"D313A509-35AE-4EA3-9EDC-20CA98293D99"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5137-3:*:*:*:*:*:*:*","matchCriteriaId":"B84531E0-D82D-43AE-A708-B12C34984B70"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5137-4:*:*:*:*:*:*:*","matchCriteriaId":"9106FF80-627C-40E1-80E1-E574EB9A6B8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5137-5:*:*:*:*:*:*:*","matchCriteriaId":"F46220E7-B924-49D4-B866-3EA6B52F4D45"},{"vulnerable":true,"criteria":"cpe:2.3:a:trevor_mckay:cumin:0.1.5192-1:*:*:*:*:*:*:*","matchCriteriaId":"CACA1231-8272-40A9-B7B3-0141E0F1D7A7"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*","matchCriteriaId":"C60FA8B1-1802-4522-A088-22171DCF7A93"}]}]}],"references":[{"url":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1278.html","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1281.html","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/50660","source":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/55618","source":"secalert@redhat.com"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78776","source":"secalert@redhat.com"},{"url":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1278.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1281.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/50660","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/55618","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78776","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'","evaluatorImpact":"Per: http://rhn.redhat.com/errata/RHSA-2012-1278.html\r\n\r\n\" An authenticated user able to\r\npre-set the Cumin session cookie in a victim's browser could possibly use\r\nthis flaw to steal the victim's session after they log into Cumin.\""}}]}