Executive brief
docuFORM Managed Print Service Client is a tool used to manage and monitor corporate printing and scanning infrastructure. A security flaw in the login process allows an attacker to potentially hijack a user's session by fixing their session identifier before they log in. If successful, an attacker could gain unauthorized access to the application, potentially compromising print management operations and sensitive document workflows.
Technical details
The docuFORM Managed Print Service Client (also referred to as FSM Client) version 11.11c is vulnerable to session fixation (CWE-384). The application fails to generate a new session identifier after a user successfully authenticates. An attacker can exploit this by pre-setting a session ID and inducing a victim to log in using that specific ID (typically via a crafted link or social engineering). Once the victim authenticates, the attacker can use the known session ID to hijack the authenticated session. The vendor has reportedly released a fix for this issue.
Affected products
- docuFORM Managed Print Service Client (FSM Client) 11.11c
Timeline
- 2025-10: other: Vulnerability reported to vendor
- 2025-11: patched: Vendor published a fix
- 2026-05-11: disclosed: Public disclosure and CVE assignment