Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36957
HistorySep 06, 2022 - 11:15 a.m.

Insecure Session Management

2022-09-0611:15:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
apache iotdb
session management
validation vulnerability
authentication
session id attack

0.016 Low

EPSS

Percentile

87.6%

org.apache.iotdb:iotdb-server uses insecure session management. Lack of proper validation of session ID at checkLogin function allows an attacker to bypass the intended authentication behavior through a session id attack.

CPENameOperatorVersion
iotdb servereq0.13.0
iotdb servereq0.13.0

0.016 Low

EPSS

Percentile

87.6%

Related for VERACODE:36957