Sun NetDynamics Session ID Hijacking Vulnerability
BID:3583
Info
Sun NetDynamics Session ID Hijacking Vulnerability
| Bugtraq ID: | 3583 |
| Class: | Design Error |
| CVE: |
CVE-2001-0922 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered by Phuzzy L0gic [[email protected]] and published in an NMRC Advisory on November 26, 2001. |
| Vulnerable: |
Sun NetDynamics 5.0 Sun NetDynamics 4.1.3 Sun NetDynamics 4.1.2 Sun NetDynamics 4.1 Sun NetDynamics 4.0 |
| Not Vulnerable: | |
Discussion
Sun NetDynamics Session ID Hijacking Vulnerability
NetDynamics is an application server platform designed to provide a comprehensive solution for enterprise level portal applications.
When a user attempts to authenticate to NetDynamics, they are given a session id, and a random unique identifier. When a subsequent user authenticates successfully, these values may be used for a brief period of time to execute a command as that subsequent user.
An attacker with knowledge of the NetDynamics command structure may be able to hijack that user account, gaining full control over it.
It is possible that earlier versions of NetDynamics are also vulnerable.
NetDynamics is an application server platform designed to provide a comprehensive solution for enterprise level portal applications.
When a user attempts to authenticate to NetDynamics, they are given a session id, and a random unique identifier. When a subsequent user authenticates successfully, these values may be used for a brief period of time to execute a command as that subsequent user.
An attacker with knowledge of the NetDynamics command structure may be able to hijack that user account, gaining full control over it.
It is possible that earlier versions of NetDynamics are also vulnerable.
Solution / Fix
Sun NetDynamics Session ID Hijacking Vulnerability
Solution:
Phuzzy L0gic [[email protected]] suggests that not allowing multiple logins from the same domain may help detect this attack.
Solution:
Phuzzy L0gic [[email protected]] suggests that not allowing multiple logins from the same domain may help detect this attack.