CVE-2025-22216 - Citrix UAA Session Hijacking

CVE ID : CVE-2025-22216 Published : Jan. 31, 2025, 6:15 a.m. | 2 hours, 29 minutes ago Description : A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Jan 31, 2025 - 09:45
 0  1
CVE-2025-22216 - Citrix UAA Session Hijacking
CVE ID : CVE-2025-22216
Published : Jan. 31, 2025, 6:15 a.m. | 2 hours, 29 minutes ago
Description : A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...