IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
BID:102340
Info
IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
| Bugtraq ID: | 102340 |
| Class: | Design Error |
| CVE: |
CVE-2017-1270 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2017 12:00AM |
| Updated: | Dec 18 2017 12:00AM |
| Credit: | IBM X-Force Ethical Hacking Team: Ron Craig, Warren Moynihan, Jonathan Fitz-Gerald, John Zuccato, Rodney Ryan, Chris Shepherd, Dmitriy Beryoza |
| Vulnerable: |
IBM Security Guardium 10.0.1 IBM Security Guardium 10.1.3 IBM Security Guardium 10.1.2 IBM Security Guardium 10.1 IBM Security Guardium 10.0 |
| Not Vulnerable: | |
Discussion
IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
IBM Security Guardium is prone to a session-hijacking vulnerability.
An attacker can leverage this issue to gain unauthorized access to the affected application.
IBM Security Guardium Versions 10.0, 10.0.1, 10.1, 10.1.2, and 10.1.3 are vulnerable.
IBM Security Guardium is prone to a session-hijacking vulnerability.
An attacker can leverage this issue to gain unauthorized access to the affected application.
IBM Security Guardium Versions 10.0, 10.0.1, 10.1, 10.1.2, and 10.1.3 are vulnerable.
Exploit / POC
IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Security Guardium CVE-2017-1270 Session Hijacking Vulnerability
References:
References: