PT-2022-2699 · Johnson Controls · Metasys Extended Application/Data Server+2

Published

2022-04-14

·

Updated

2022-04-25

·

CVE-2021-36205

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Metasys Application and Data Server (ADS) (affected versions not specified) Metasys Extended Application and Data Server (ADX) (affected versions not specified) Metasys Open Application Server (OAS) (affected versions not specified)
Description The issue is related to incomplete session token clearance. Under certain circumstances, the session token is not cleared on logout, which could allow a remote attacker to obtain the session token of an authenticated user.
Recommendations For Metasys Application and Data Server (ADS), consider implementing a workaround to ensure session tokens are properly cleared on logout. For Metasys Extended Application and Data Server (ADX), restrict access to sensitive areas until a proper fix for the session token clearance issue is applied. For Metasys Open Application Server (OAS), as a temporary measure, manually invalidate session tokens after each use to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03193
CVE-2021-36205

Affected Products

Metasys Application/Data Server
Metasys Extended Application/Data Server
Metasys Open Application Server