A session fixation vulnerability in South River Technologies Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the servers authentication if they can trick an administrator into authorizating a session id of their choosing
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Titan_mft_server | Southrivertech | * | 2.0.18 (excluding) |
Such a scenario is commonly observed when: