TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
BID:47921
Info
TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 47921 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2020 CVE-2011-2021 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2011 12:00AM |
| Updated: | May 19 2011 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
TIBCO iProcess Workspace 11.3.1 TIBCO iProcess Engine 11.1.3 |
| Not Vulnerable: | |
Discussion
TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
The TIBCO iProcess Suite is prone to a cross-site scripting vulnerability and a session-fixation vulnerability.
Successfully exploiting these vulnerabilities can allow attackers to execute arbitrary script code in a user's browser in the context of the webserver process, access sensitive data, or hijack a user's session.
The following products are vulnerable:
TIBCO iProcess Engine versions prior to 11.1.3.
TIBCO iProcess Workspace (Browser) versions prior to 11.3.1.
The TIBCO iProcess Suite is prone to a cross-site scripting vulnerability and a session-fixation vulnerability.
Successfully exploiting these vulnerabilities can allow attackers to execute arbitrary script code in a user's browser in the context of the webserver process, access sensitive data, or hijack a user's session.
The following products are vulnerable:
TIBCO iProcess Engine versions prior to 11.1.3.
TIBCO iProcess Workspace (Browser) versions prior to 11.3.1.
Exploit / POC
TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
Solution / Fix
TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TIBCO iProcess Suite Session Fixation and Cross Site Scripting Vulnerabilities
References:
References:
- General FAQ (TIBCO)
- TIBCO Homepage (TIBCO)
- TIBCO iProcess Suite (TIBCO)
- TIBCO iProcess vulnerabilities (TIBCO)