CVE-2014-9386: Zenoss Core

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

Affected products

  • Zenoss Zenoss Core: up to and including 4.2.5; version 2.4.0 only; version 2.4.5 only; version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; …

Published 2014-12-15. Last modified 2026-06-17.