First published: Thu Jun 14 2018(Updated: )
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Privileged Access Manager | >=2.0.0<3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9026 is classified as a high severity vulnerability due to its potential for session hijacking.
To fix CVE-2018-9026, update CA Privileged Access Manager to version 3.0.0 or later.
CVE-2018-9026 is a session fixation vulnerability that allows attackers to hijack user sessions.
CVE-2018-9026 affects users of CA Privileged Access Manager version 2.x.
Yes, CVE-2018-9026 can be exploited remotely by attackers through specially crafted requests.