Lucene search

K
ibmIBM47445A084D53907ACA23EFB84A13C708346EB932236F719244C2ACBF63CF1797
HistoryFeb 11, 2021 - 6:06 p.m.

Security Bulletin: IBM Security Verify Information Queue does not sufficiently safeguard session IDs from session fixation attacks (CVE-2021-20411)

2021-02-1118:06:13
www.ibm.com
9
ibm
security
verify
information
queue
session
identifier
vulnerability
fix
cve-2021-20411
docker
hub
repository
ibm security information queue starter kit

EPSS

0.001

Percentile

20.0%

Summary

The web server in IBM Security Verify Information Queue (ISIQ) does not always update the session identifier when a new user logs in. This could allow a session fixation attack in which a previously used session identifier gets commandeered by an impersonator. As of v10.0.0, ISIQ now consistently generates a new session identifier for each login to prevent a session fixation attack.

Vulnerability Details

CVEID:CVE-2021-20411
**DESCRIPTION:**IBM Security Verify Information Queue could allow a user to impersonate another user on the system due to incorrectly updating the session identifier.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196191 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Verify Information Queue 1.0.6, 1.0.7

Remediation/Fixes

Download and install the latest IBM Security Verify Information Queue images (tagged at 10.0.0 or greater) from the Docker Hub repository. The instructions for accessing and deploying the images can be found on the ISIQ starter kit page: <https://www.ibm.com/support/pages/ibm-security-information-queue-starter-kit&gt;

Workarounds and Mitigations

None

EPSS

0.001

Percentile

20.0%

Related for 47445A084D53907ACA23EFB84A13C708346EB932236F719244C2ACBF63CF1797