CVE-2018-1962: Medium severity ibm security identity manager vulnerability
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-1962.
What is the severity level of CVE-2018-1962?
The severity level of CVE-2018-1962 is medium.
How can an attacker exploit this vulnerability?
An attacker with local access can exploit this vulnerability by logging into a closed browser session using the session tokens that are not invalidated when the logout button is pressed.
Is there a fix available for this vulnerability?
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM Security Identity Manager documentation for details on how to apply the fix.
Where can I find more information about CVE-2018-1962?
You can find more information about CVE-2018-1962 on the IBM Support website, SecurityFocus, and the IBM X-Force exchange.