Junglewise Threat Intelligence

CVE-2025-10228: Rolantis Agentis session fixation in Agentis platform

CVE-2025-10228 · Severity: high · CVSS 8.8 · Published 2025-10-14

Technologies: Rolantis Information Technologies Agentis. Vendors: Rolantis Information Technologies.

Executive brief

A session fixation vulnerability has been identified in Rolantis Agentis, a software platform used for business information management. This flaw allows an attacker to pre-determine a user's session ID, effectively hijacking their account once they log in. If exploited, an attacker could gain full access to a user's account, potentially leading to the theft of sensitive corporate data or unauthorized administrative actions.

Technical details

A session fixation vulnerability (CWE-384) exists in Rolantis Information Technologies Agentis versions prior to 4.44. The application fails to invalidate or renew the session identifier upon a successful user login, allowing an attacker to supply a known session ID to a victim. If the victim authenticates using that ID, the attacker can hijack the authenticated session. This attack is delivered over the network and requires minimal user interaction (UI:R), potentially resulting in a full compromise of confidentiality, integrity, and availability. Users are advised to upgrade to version 4.44 or later to resolve the issue.

Affected products

  • Rolantis Information Technologies Agentis before 4.44

Timeline

  • 2025-10-14: disclosed: Initial publication of CVE-2025-10228
  • 2025-10-14: advisory: Advisory released by USOM (TR-CERT)

References

Related threats