IBM Lotus Domino Web Access Session Hijacking Vulnerability
BID:19966
CVE-2006-4763 |Info
IBM Lotus Domino Web Access Session Hijacking Vulnerability
| Bugtraq ID: | 19966 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Sep 12 2006 10:42PM |
| Credit: | Dave Ferguson is credited with the discovery of this vulnerability. |
| Vulnerable: |
IBM Lotus Domino Web Access 7.0.1 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino Web Access Session Hijacking Vulnerability
IBM Lotus Domino Web Access is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to authenticate to the application as any user provided that the user's authentication credentials are still on the server. This may lead to other attacks.
Version 7.0.1 is vulnerable to this issue; other versions may also be affected.
IBM Lotus Domino Web Access is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to authenticate to the application as any user provided that the user's authentication credentials are still on the server. This may lead to other attacks.
Version 7.0.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
IBM Lotus Domino Web Access Session Hijacking Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
IBM Lotus Domino Web Access Session Hijacking Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
IBM Lotus Domino Web Access Session Hijacking Vulnerability
References:
References: