PT-2001-2248 · Rsa · Rsa Bsafe Ssl-J

Publicado

2001-09-12

·

Atualizado

2021-11-08

·

CVE-2001-1105

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RSA BSAFE SSL-J versions 3.0 through 3.1
Description The issue allows remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure, due to the caching of session IDs from failed login attempts.
Recommendations For RSA BSAFE SSL-J versions 3.0 through 3.1, consider disabling the session ID caching mechanism to prevent attackers from bypassing SSL client authentication.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1105

Produtos afetados

Rsa Bsafe Ssl-J