Macromedia JRun Management Console Administrative Session Fixation Vulnerability
BID:11414
Info
Macromedia JRun Management Console Administrative Session Fixation Vulnerability
| Bugtraq ID: | 11414 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2004 12:00AM |
| Updated: | Oct 14 2004 12:00AM |
| Credit: | Discovery is credited to ACROS Security. |
| Vulnerable: |
Macromedia JRun 4.0 SP1a Macromedia JRun 4.0 SP1 Macromedia JRun 4.0 build 61650 Macromedia JRun 4.0 |
| Not Vulnerable: | |
Discussion
Macromedia JRun Management Console Administrative Session Fixation Vulnerability
Macromedia JRun is prone to session fixation vulnerability. This issue exists in the Management Console.
The application is reported prone to session fixation vulnerability. This attack can allow an attacker to set a session ID in a user's browser and hijack the user's session upon authentication to JRun.
This issue can allow remote attackers to bypass authentication checks, and possibly allow them to gain administrative access to the web application.
This issue was originally reported in BID 11245 (Macromedia JRun Multiple Remote Vulnerabilities). It is now being separated and assigned a new BID.
Macromedia JRun is prone to session fixation vulnerability. This issue exists in the Management Console.
The application is reported prone to session fixation vulnerability. This attack can allow an attacker to set a session ID in a user's browser and hijack the user's session upon authentication to JRun.
This issue can allow remote attackers to bypass authentication checks, and possibly allow them to gain administrative access to the web application.
This issue was originally reported in BID 11245 (Macromedia JRun Multiple Remote Vulnerabilities). It is now being separated and assigned a new BID.
Exploit / POC
Macromedia JRun Management Console Administrative Session Fixation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Macromedia JRun Management Console Administrative Session Fixation Vulnerability
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
References
Macromedia JRun Management Console Administrative Session Fixation Vulnerability
References:
References:
- Macromedia JRun Support Center - Updaters (Macromedia)
- MPSB04-08 - Cumulative Security Patch available for JRun server (Macromedia)
- Session Fixation Vulnerability in Web-based Applications (ACROS Security)