top of page

Sentence 40

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.

Actual

  • Exploit mechanism: session fixation/hijacking

  • Exploit objective: force a user to utilize a cookie that may be known to an attacker

  • Attack pathway: session variable

Predicted

  • Exploit mechanism: not renewing a session variable

  • Exploit objective: session fixation/hijacking vulnerability

  • Attack pathway: force a user to utilize a cookie that may be known to an attacker

bottom of page