PT-2018-9778 · Solarwinds · Serv-U Mft
Publicado
2018-05-16
·
Atualizado
2018-06-25
·
CVE-2018-10240
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
SolarWinds Serv-U MFT versions prior to 15.1.6 HFv1
Description:
The issue allows an attacker to brute-force a low-entropy session token assigned to authenticated users. This token can be used in requests as a URL parameter instead of a session cookie, potentially leading to session hijacking.
Recommendations:
For versions prior to 15.1.6 HFv1, update to version 15.1.6 HFv1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application that rely on session cookies to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Serv-U Mft