Vulnerability CVE-2023-26288


Published: 2024-07-30   Modified: 2024-07-31

Description:
IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

Type:

CWE-613

(Insufficient Session Expiration)

 References:
https://www.ibm.com/support/pages/node/7161538
https://exchange.xforce.ibmcloud.com/vulnerabilities/248477

Copyright 2024, cxsecurity.com

 

Back to Top