CVE-2021-22927
8.1HIGH
Summary
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Affected Version(s)
Citrix ADC, Citrix Gateway = Citrix ADC and Citrix Gateway 13.0-82.45 and later releases of 13.0
Citrix ADC, Citrix Gateway = Citrix ADC and Citrix Gateway 12.1-62.27 and later releases of 12.1
Citrix ADC, Citrix Gateway = Citrix ADC and NetScaler Gateway 11.1-65.22 and later releases of 11.1
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database