CVE-2011-3424
Summary
| CVE | CVE-2011-3424 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-19 12:02:00 UTC |
| Updated | 2017-08-29 01:30:00 UTC |
| Description | Session fixation vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to hijack web sessions via unspecified vectors. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 75397 | OSVDB | www.osvdb.org | |
| SecurityTracker: TIBCO Slingshot Bugs Permit Cross-Site Scripting and Session Hijacking Attacks | SECTRACK | securitytracker.com | |
| TIBCO | TIBCO® Managed File Transfer Internet Server, TIBCO® Managed File Transfer Command Center, TIBCO® Slingshot | CONFIRM | www.tibco.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 404 Not Found | CONFIRM | www.tibco.com | |
| TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| TIBCO Managed File Transfer Products Cross-Site Scripting and Session Fixation Vulnerabilities - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.