IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mq | Ibm | 8.0.0.4 (including) | 8.0.0.12 (including) |
Mq | Ibm | 9.0.0.0 (including) | 9.0.0.6 (including) |
Mq | Ibm | 9.1.0 (including) | 9.1.2 (including) |
Mq | Ibm | 9.1.0.0 (including) | 9.1.0.2 (including) |
Such a scenario is commonly observed when: