PT-2018-9778 · Solarwinds · Serv-U Mft

Published

2018-05-16

·

Updated

2018-06-25

·

CVE-2018-10240

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: SolarWinds Serv-U MFT versions prior to 15.1.6 HFv1
Description: The issue allows an attacker to brute-force a low-entropy session token assigned to authenticated users. This token can be used in requests as a URL parameter instead of a session cookie, potentially leading to session hijacking.
Recommendations: For versions prior to 15.1.6 HFv1, update to version 15.1.6 HFv1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application that rely on session cookies to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10240

Affected Products

Serv-U Mft