CVE-2016-8638 Information
Description
A vulnerability in ipsilon 2.0 before 2.0.2 1.2 before 1.2.1 1.1 before 1.1.2 and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a \SAML2 multi-session vulnerability.\
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Reference
http://rhn.redhat.com/errata/RHSA-2016-2809.html http://www.securityfocus.com/bid/94439 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8638 https://ipsilon-project.org/advisory/CVE-2016-8638.txt https://ipsilon-project.org/release/2.1.0.html https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461c
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
9.1
Share on: