Description
A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when using Undertow was found despite Undertow switching the session ID after authentication.
Remediation
References
Related Vulnerabilities
Frontaccounting Other Vulnerability (CVE-2007-4279)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4194)
Oracle Application Server Other Vulnerability (CVE-2007-0281)
WordPress Plugin HTML5 AV Manager for WordPress 'custom.php' Arbitrary File Upload (0.2.7)