CVE Vulnerabilities

CVE-2019-4227

Session Fixation

Published: Oct 04, 2019 | Modified: Dec 02, 2022
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Mq Ibm 8.0.0.4 (including) 8.0.0.12 (including)
Mq Ibm 9.0.0.0 (including) 9.0.0.6 (including)
Mq Ibm 9.1.0 (including) 9.1.2 (including)
Mq Ibm 9.1.0.0 (including) 9.1.0.2 (including)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References