PT-2018-9778 · Solarwinds · Serv-U Mft
Published
2018-05-16
·
Updated
2018-06-25
·
CVE-2018-10240
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
SolarWinds Serv-U MFT versions prior to 15.1.6 HFv1
Description:
The issue allows an attacker to brute-force a low-entropy session token assigned to authenticated users. This token can be used in requests as a URL parameter instead of a session cookie, potentially leading to session hijacking.
Recommendations:
For versions prior to 15.1.6 HFv1, update to version 15.1.6 HFv1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application that rely on session cookies to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serv-U Mft