VYPR
Unrated severityNVD Advisory· Published May 29, 2018· Updated Sep 16, 2024

CVE-2018-1375

CVE-2018-1375

Description

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 137776.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 fails to renew session identifiers after authentication, enabling session fixation attacks.

Vulnerability

IBM Security Guardium Big Data Intelligence (SonarG) version 3.1 does not update the session identifier after a successful authentication. This flaw allows an attacker to potentially force a user to utilize a known session cookie, leading to session fixation or hijacking [1]. The vulnerability is present in the session management logic of the application.

Exploitation

An attacker must first obtain a valid session identifier (e.g., by visiting the application or crafting a malicious link) and then trick an authenticated user into using that same session identifier before or during login. This can be achieved through social engineering, cross-site scripting, or other means that force the user to accept a predetermined cookie. After the user authenticates, the session identifier remains unchanged, granting the attacker access to the authenticated session [1].

Impact

Successful exploitation allows an attacker to hijack an authenticated user's session, leading to unauthorized access to sensitive information. The CVSS v3.0 base score is 5.9 (Medium) with a vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating high confidentiality impact but no integrity or availability impact [1].

Mitigation

IBM has addressed this vulnerability in a security update. Users should apply the latest fix as described in the IBM Security Bulletin [1]. No workarounds are available; the bulletin explicitly states "Workarounds and Mitigations: None" [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.