Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
BID:61739
Info
Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
| Bugtraq ID: | 61739 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4128 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2013 12:00AM |
| Updated: | Oct 17 2013 05:44AM |
| Credit: | Wolf-Dieter Fink of the Red Hat GSS Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
JBoss Enterprise Application Platform is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
JBoss Enterprise Application Platform is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Exploit / POC
Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat JBoss Enterprise Application Platform CVE-2013-4128 Session Fixation Vulnerability
References:
References: