First published: Sun Oct 26 2014(Updated: )
F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Analytics | =11.0.0 | |
F5 BIG-IP Analytics | =11.1.0 | |
F5 BIG-IP Analytics | =11.2.0 | |
F5 BIG-IP Analytics | =11.2.1 | |
F5 BIG-IP Analytics | =11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7408 is considered to have a medium severity level due to the predictable session cookie vulnerability.
To fix CVE-2013-7408, upgrade to F5 BIG-IP Analytics version 11.4.0 or later.
CVE-2013-7408 can allow remote attackers to exploit session cookies, potentially gaining unauthorized access.
CVE-2013-7408 affects F5 BIG-IP Analytics versions 11.0.0 to 11.3.0.
There are no documented workarounds for CVE-2013-7408, so upgrading is the recommended solution.