IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid users session. IBM X-Force ID: 120257
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_appscan | Ibm | 9.0.0.0 (including) | 9.0.0.0 (including) |
Security_appscan | Ibm | 9.0.0.1 (including) | 9.0.0.1 (including) |
Security_appscan | Ibm | 9.0.1.0 (including) | 9.0.1.0 (including) |
Security_appscan | Ibm | 9.0.1.1 (including) | 9.0.1.1 (including) |
Security_appscan | Ibm | 9.0.2.0 (including) | 9.0.2.0 (including) |
Security_appscan | Ibm | 9.0.2.1 (including) | 9.0.2.1 (including) |
Security_appscan | Ibm | 9.0.3.0 (including) | 9.0.3.0 (including) |
Security_appscan | Ibm | 9.0.3.1 (including) | 9.0.3.1 (including) |
Security_appscan | Ibm | 9.0.3.4 (including) | 9.0.3.4 (including) |
Security_appscan | Ibm | 9.0.3.5 (including) | 9.0.3.5 (including) |
Such a scenario is commonly observed when: