CRITICAL🇵🇱 Wersja polska

CVE-2024-8643

CVSS 9.3v4.0pub. 2024-09-27upd. 2026-06-02

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

🤖 AI Analysis
How it works

Session Fixation is when an attacker is able to impose a pre-known session identifier on a victim, and the application accepts it without generating a new token after login. When the user authenticates using the previously established identifier, the attacker can use the same identifier to gain access to the victim's session. The vulnerability can be further exploited to conduct Brute Force attacks on session tokens or Session Hijacking.

Impact

An attacker can fully hijack the session of an authenticated user, gaining unauthorized access to their account and data processed by the ValeApp application. Depending on the privileges of the hijacked account, it is possible to compromise the confidentiality, integrity, and availability of data.

Mitigation & patch

ValeApp should be updated to version v2.0.0 or newer, in which the vulnerability has been fixed. It is also recommended to invalidate all active user sessions after implementing the update and to verify session management configuration in accordance with the manufacturer's guidelines available in the references.

Who is affected

Oceanicsoft ValeApp in all versions before v2.0.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Oceanicsoft Valeapp

    APP
    Oceanicsoft
    < 2.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-8644CRITICAL9.3PL ✓same product

Przechowywanie wrażliwych danych w ciasteczku w postaci niezaszyfrowanej — Oceanic Software ValeApp

CVE-2024-8607HIGH8.7same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic ...

CVE-2024-8608HIGH7.2same product

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in O...

CVE-2024-8609HIGH8.8same product

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System...