First published: Sat Sep 17 2011(Updated: )
Session fixation vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to hijack web sessions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Managed File Transfer Command Center | <=7.1.0 | |
TIBCO Managed File Transfer Command Center | =6.7 | |
TIBCO Managed File Transfer Command Center | =7.0 | |
TIBCO Managed File Transfer Command Center | =7.0.1 | |
TIBCO Managed File Transfer Internet Server | <=7.1.0 | |
TIBCO Managed File Transfer Internet Server | =6.7 | |
TIBCO Managed File Transfer Internet Server | =7.0 | |
TIBCO Managed File Transfer Internet Server | =7.0.1 | |
TIBCO Slingshot | <=1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3424 is considered a moderate severity vulnerability due to the potential for session hijacking by remote attackers.
To fix CVE-2011-3424, upgrade TIBCO Managed File Transfer Internet Server and Command Center to version 7.1.1 or later, and TIBCO Slingshot to version 1.8.1 or later.
CVE-2011-3424 affects TIBCO Managed File Transfer Command Center versions up to 7.1.0, Managed File Transfer Internet Server versions up to 7.1.0, and TIBCO Slingshot versions up to 1.8.0.
CVE-2011-3424 is a session fixation vulnerability that allows attackers to hijack web sessions.
Organizations using the affected versions of TIBCO Managed File Transfer solutions may be impacted by CVE-2011-3424.