Podatność CVE-2023-26288


Publikacja: 2024-07-30   Modyfikacja: 2024-07-31

Opis:
IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

Typ:

CWE-613

(Insufficient Session Expiration)

 Referencje:
https://www.ibm.com/support/pages/node/7161538
https://exchange.xforce.ibmcloud.com/vulnerabilities/248477

Copyright 2024, cxsecurity.com

 

Back to Top