A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Datamodule_compactplus | Bbraun | a10 (including) | a10 (including) |
Datamodule_compactplus | Bbraun | a11 (including) | a11 (including) |
Such a scenario is commonly observed when: