Executive brief
A session fixation vulnerability has been identified in Rolantis Agentis, a software platform used for business information management. This flaw allows an attacker to pre-determine a user's session ID, effectively hijacking their account once they log in. If exploited, an attacker could gain full access to a user's account, potentially leading to the theft of sensitive corporate data or unauthorized administrative actions.
Technical details
A session fixation vulnerability (CWE-384) exists in Rolantis Information Technologies Agentis versions prior to 4.44. The application fails to invalidate or renew the session identifier upon a successful user login, allowing an attacker to supply a known session ID to a victim. If the victim authenticates using that ID, the attacker can hijack the authenticated session. This attack is delivered over the network and requires minimal user interaction (UI:R), potentially resulting in a full compromise of confidentiality, integrity, and availability. Users are advised to upgrade to version 4.44 or later to resolve the issue.
Affected products
- Rolantis Information Technologies Agentis before 4.44
Timeline
- 2025-10-14: disclosed: Initial publication of CVE-2025-10228
- 2025-10-14: advisory: Advisory released by USOM (TR-CERT)