CVE-2018-17199
30.01.2019, 22:29
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.0 ≤ 𝑥 ≤ 2.4.37 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
netapp | santricity_cloud_connector | - |
netapp | storage_automation_store | - |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
oracle | enterprise_manager_ops_center | 12.3.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References