First published: Thu May 09 2019(Updated: )
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are presented with information for Spectrum Control Application. IBM X-Force ID: 157064.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Control | >=5.2.8<=5.2.17.2 | |
IBM Spectrum Control | >=5.3.0<=5.3.1 | |
IBM Tivoli Storage Productivity Center | >=5.2.0<=5.2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4072 is classified as a moderate severity vulnerability.
To mitigate CVE-2019-4072, it is recommended to upgrade IBM Spectrum Control and IBM Tivoli Storage Productivity Center to the latest version that addresses this issue.
CVE-2019-4072 affects various versions of IBM Spectrum Control and IBM Tivoli Storage Productivity Center, particularly versions below 5.2.18 and 5.3.1.
CVE-2019-4072 allows unauthorized access by permitting users to remain logged in after logging out, potentially exposing sensitive information.
As a temporary workaround for CVE-2019-4072, users should ensure to close their session completely and avoid using the back button after logging out.