CVE-2019-4072: Medium severity ibm spectrum control vulnerability
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are presented with information for Spectrum Control Application. IBM X-Force ID: 157064.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4072?
CVE-2019-4072 is classified as a moderate severity vulnerability.
How do I fix CVE-2019-4072?
To mitigate CVE-2019-4072, it is recommended to upgrade IBM Spectrum Control and IBM Tivoli Storage Productivity Center to the latest version that addresses this issue.
What affects the CVE-2019-4072 vulnerability?
CVE-2019-4072 affects various versions of IBM Spectrum Control and IBM Tivoli Storage Productivity Center, particularly versions below 5.2.18 and 5.3.1.
What is the impact of CVE-2019-4072 on users?
CVE-2019-4072 allows unauthorized access by permitting users to remain logged in after logging out, potentially exposing sensitive information.
Is there a workaround for CVE-2019-4072?
As a temporary workaround for CVE-2019-4072, users should ensure to close their session completely and avoid using the back button after logging out.