CVE-2017-1152Session Fixation in Corporation Financial Transaction Manager

CWE-384Session Fixation4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 67.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 17

Description

IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2g7h-x5vj-qp64: IBM Financial Transaction Manager 32022-05-17
CVEList
CVE-2017-1152: IBM Financial Transaction Manager 32017-04-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - '0x224000 IOCTL (WmiQueryAllData)' Kernel WMIDataDevice Pool Memory Disclosure2017-06-21
CVE-2017-1152 — Session Fixation | cvebase