Описание
Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.
Комментарий
Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.1.2 (включая)
Одно из
cpe:2.3:a:tibco:iprocess_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.4:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.3.5:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.4:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.4.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.5:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.6:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.6.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:10.6.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:11.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_engine:11.1.1:*:*:*:*:*:*:*
Конфигурация 2Версия до 11.3 (включая)
Одно из
cpe:2.3:a:tibco:iprocess_workspace:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_workspace:11.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_workspace:11.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:iprocess_workspace:11.2:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00677
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.
EPSS
Процентиль: 71%
0.00677
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other