First published: Mon Feb 04 2019(Updated: )
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | >=7.0.1<=7.0.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1962.
The severity level of CVE-2018-1962 is medium.
An attacker with local access can exploit this vulnerability by logging into a closed browser session using the session tokens that are not invalidated when the logout button is pressed.
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM Security Identity Manager documentation for details on how to apply the fix.
You can find more information about CVE-2018-1962 on the IBM Support website, SecurityFocus, and the IBM X-Force exchange.