Vulnerability CVE-2024-38315


Published: 2024-09-16

Description:
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

Type:

CWE-613

(Insufficient Session Expiration)

 References:
https://www.ibm.com/support/pages/node/7168379
https://exchange.xforce.ibmcloud.com/vulnerabilities/294742

Copyright 2024, cxsecurity.com

 

Back to Top