CVE-2019-18946: Session fixation
Published Feb 26, 2021
·Updated
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.
Affected Software
1 affected component
MicroFocus Solutions Business Manager<11.7.1
Remediation
Information
Upgrade SBM to 11.7.1 or later
Event History
Feb 26, 2021
CVE Published
via MITRE·03:04 AM
Data Sourced
via MITRE·03:04 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-18946?
CVE-2019-18946 has been rated as a medium severity vulnerability due to session fixation issues.
2
How do I fix CVE-2019-18946?
To fix CVE-2019-18946, upgrade your Micro Focus Solutions Business Manager to version 11.7.1 or later.
3
What are the implications of CVE-2019-18946?
CVE-2019-18946 allows an attacker to hijack users' sessions through session fixation.
4
Which versions are affected by CVE-2019-18946?
CVE-2019-18946 affects all versions of Micro Focus Solutions Business Manager prior to 11.7.1.
5
Is there a workaround for CVE-2019-18946?
There is no official workaround for CVE-2019-18946; the recommended action is to update to the patched version.