First published: Fri May 20 2011(Updated: )
Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO iProcess Engine | <=11.1.2 | |
TIBCO iProcess Engine | =10.3.0 | |
TIBCO iProcess Engine | =10.3.1 | |
TIBCO iProcess Engine | =10.3.2 | |
TIBCO iProcess Engine | =10.3.3 | |
TIBCO iProcess Engine | =10.3.4 | |
TIBCO iProcess Engine | =10.3.5 | |
TIBCO iProcess Engine | =10.4 | |
TIBCO iProcess Engine | =10.4.1 | |
TIBCO iProcess Engine | =10.5 | |
TIBCO iProcess Engine | =10.6 | |
TIBCO iProcess Engine | =10.6.0 | |
TIBCO iProcess Engine | =10.6.1 | |
TIBCO iProcess Engine | =10.6.2 | |
TIBCO iProcess Engine | =11.0 | |
TIBCO iProcess Engine | =11.1.1 | |
TIBCO iProcess Workspace | <=11.3 | |
TIBCO iProcess Workspace | =11.0 | |
TIBCO iProcess Workspace | =11.1 | |
TIBCO iProcess Workspace | =11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2021 is considered a moderate severity vulnerability due to its potential for session hijacking.
To fix CVE-2011-2021, ensure that you upgrade to TIBCO iProcess Engine version 11.1.3 or higher and TIBCO iProcess Workspace version 11.3.1 or higher.
CVE-2011-2021 can be exploited by attackers to hijack user sessions through session fixation techniques.
CVE-2011-2021 affects TIBCO iProcess Engine versions 10.3.0 to 11.1.2, including 10.5, 10.6, and 11.0.
Yes, TIBCO iProcess Workspace versions up to 11.3 are also vulnerable to CVE-2011-2021.