CVE-2021-41553 describes a critical session management vulnerability in ARCHIBUS Web Central version 21.3.3.815, where the application could assign a session token already in use or allow client-side manipulation of the JSESSIONID. This flaw permitted unauthorized access to user accounts without credentials. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, this vulnerability affects an unsupported product version, with fixes available in newer, supported releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.3.3.815CPE matchmatch criteria | cpe:2.3:a:archibus:web_central:21.3.3.815:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.