A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Application_delivery_controller_firmware | Citrix | 11.1 (including) | 11.1-65.22 (excluding) |
Application_delivery_controller_firmware | Citrix | 12.1 (including) | 12.1-62.27 (excluding) |
Application_delivery_controller_firmware | Citrix | 13.0 (including) | 13.0-82.45 (excluding) |
Such a scenario is commonly observed when: