High severity8.1NVD Advisory· Published Aug 5, 2021· Updated Jun 17, 2026
CVE-2021-22927
CVE-2021-22927
Description
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Affected products
6cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:gateway:*:*:*:*:*:*:*:*range: >=12.1,<12.1-62.27
- (no CPE)range: = 13.0-82.45
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*Range: >=11.1,<11.1-65.22
- cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*Range: >=11.1,<11.1-65.22
- Citrix/ADC / Gatewaydescription
- Range: = 13.0-82.45
Patches
Vulnerability mechanics
References
1- support.citrix.com/article/CTX319135nvdVendor Advisory
News mentions
0No linked articles in our index yet.