The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.
2007-11-05T17:46:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | access_gateway | 4.0 | Yes |
Application | citrix | access_gateway | 4.2 | Yes |
Application | citrix | access_gateway | 4.5 | Yes |
Application | citrix | access_gateway | 4.5 | Yes |