PT-2022-2699 · Johnson Controls · Metasys Extended Application/Data Server+2
Published
2022-04-14
·
Updated
2022-04-25
·
CVE-2021-36205
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Metasys Application and Data Server (ADS) (affected versions not specified)
Metasys Extended Application and Data Server (ADX) (affected versions not specified)
Metasys Open Application Server (OAS) (affected versions not specified)
Description
The issue is related to incomplete session token clearance. Under certain circumstances, the session token is not cleared on logout, which could allow a remote attacker to obtain the session token of an authenticated user.
Recommendations
For Metasys Application and Data Server (ADS), consider implementing a workaround to ensure session tokens are properly cleared on logout.
For Metasys Extended Application and Data Server (ADX), restrict access to sensitive areas until a proper fix for the session token clearance issue is applied.
For Metasys Open Application Server (OAS), as a temporary measure, manually invalidate session tokens after each use to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasys Application/Data Server
Metasys Extended Application/Data Server
Metasys Open Application Server