First published: Fri Sep 02 2011(Updated: )
Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire | =3.0.0 | |
TIBCO Spotfire | =3.3.0 | |
TIBCO Spotfire | =3.1.1 | |
TIBCO Spotfire | =3.1.0 | |
TIBCO Spotfire Analytics Server | <=10.0.1 | |
TIBCO Spotfire | =3.2.0 | |
TIBCO Spotfire Analytics Server | =10.0.0 | |
TIBCO Spotfire | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3133 is considered to be high as it allows remote attackers to hijack web sessions.
To fix CVE-2011-3133, upgrade TIBCO Spotfire Server and Spotfire Analytics Server to the latest versions that are not affected.
CVE-2011-3133 affects TIBCO Spotfire Server versions 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1.
CVE-2011-3133 is a session fixation vulnerability.
An attacker exploiting CVE-2011-3133 can hijack web sessions, potentially gaining unauthorized access to user accounts.