The web portal interface in Citrix Access Gateway (aka Citrix...
Vulnerability Description
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0011
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2007/2583
- http://secunia.com/advisories/26143
- http://www.securityfocus.com/bid/24975
- http://osvdb.org/45288
- http://securitytracker.com/id?1018435
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35510
- http://support.citrix.com/article/CTX112803
- http://www.securityfocus.com/archive/1/482626/100/100/threaded
- http://support.citrix.com/article/CTX113814
More from citrix
View All →Affected Vendor
citrix
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.