CVE-2020-10714
23.09.2020, 13:15
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | wildfly_elytron | 𝑥 < 1.11.3 |
redhat | codeready_studio | 12.0 |
redhat | descision_manager | 7.0 |
redhat | jboss_fuse | 7.0.0 |
redhat | process_automation | 7.0 |
netapp | oncommand_insight | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration