CVE-2018-12538: High severity ibm cognos analytics vulnerability
Eclipse Jetty could allow a remote attacker to hijack a user's session, caused by a flaw in the FileSessionDataStore. An attacker could exploit this vulnerability to gain access to another user's session.
Other sources
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12538?
CVE-2018-12538 is a vulnerability in Eclipse Jetty versions 9.4.0 through 9.4.8 that allows a malicious user to access and hijack other HttpSessions and delete unmatched HttpSessions stored in the FileSystem's storage.
What is the severity of CVE-2018-12538?
CVE-2018-12538 has a severity rating of 8.8 (high).
Which software is affected by CVE-2018-12538?
The following software are affected by CVE-2018-12538: Eclipse Jetty, NetApp E-series Santricity Management Plug-ins, NetApp E-Series SANtricity OS Controller, Netapp E-series Santricity Web Services Proxy, Netapp Element Software, Netapp Hyper Converged Infrastructure, NetApp OnCommand System Manager, Netapp Oncommand Unified Manager, IBM Cloud Pak for Automation, NetApp Snap Creator Framework, Netapp Snapcenter, Netapp Snapmanager.
How can I fix CVE-2018-12538?
To fix CVE-2018-12538, you should upgrade to a version of Eclipse Jetty that is higher than 9.4.8.
Where can I find more information about CVE-2018-12538?
You can find more information about CVE-2018-12538 at the following references: [http://www.securitytracker.com/id/1041194](http://www.securitytracker.com/id/1041194), [https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018](https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018), [https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E](https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E)