CVE-2011-3424
Summary
| CVE | CVE-2011-3424 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-19 12:02:57 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Session fixation vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to hijack web sessions via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Managed File Transfer Command Center | 6.7 | All | All | All |
| Application | Tibco | Managed File Transfer Command Center | 7.0 | All | All | All |
| Application | Tibco | Managed File Transfer Command Center | 7.0.1 | All | All | All |
| Application | Tibco | Managed File Transfer Command Center | All | All | All | All |
| Application | Tibco | Managed File Transfer Internet Server | 6.7 | All | All | All |
| Application | Tibco | Managed File Transfer Internet Server | 7.0 | All | All | All |
| Application | Tibco | Managed File Transfer Internet Server | 7.0.1 | All | All | All |
| Application | Tibco | Managed File Transfer Internet Server | All | All | All | All |
| Application | Tibco | Slingshot | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO | TIBCO® Managed File Transfer Internet Server, TIBCO® Managed File Transfer Command Center, TIBCO® Slingshot | af854a3a-2127-422b-91ae-364da2661108 | www.tibco.com | |
| www.osvdb.org/75397 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| TIBCO Managed File Transfer Products Cross-Site Scripting and Session Fixation Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker: TIBCO Slingshot Bugs Permit Cross-Site Scripting and Session Hijacking Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.tibco.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.