First published: Sun Oct 04 2015(Updated: )
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere eXtreme Scale | =7.1.0 | |
IBM WebSphere eXtreme Scale | =7.1.0.2 | |
IBM WebSphere eXtreme Scale | =7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2029 has a medium severity rating due to its potential for session hijacking.
To mitigate CVE-2015-2029, upgrade IBM WebSphere eXtreme Scale to version 7.1.0.3 or 7.1.1.1 or later.
CVE-2015-2029 affects IBM WebSphere eXtreme Scale versions before 7.1.0.3 and 7.1.1.1.
CVE-2015-2029 is classified as a session fixation vulnerability.
Yes, CVE-2015-2029 can be exploited by remote attackers to hijack web sessions.