First published: Tue Jun 25 2019(Updated: )
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager | >=9.0.1<=9.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-4152.
The severity level of CVE-2019-4152 is medium, with a severity value of 4.4.
CVE-2019-4152 is a vulnerability in IBM Security Access Manager 9.0.1 through 9.0.6 that allows attackers with local access to log into a closed browser session due to improper session expiration.
CVE-2019-4152 allows attackers with local access to login into a closed browser session in IBM Security Access Manager due to the lack of proper session expiration.
Yes, you can find references for CVE-2019-4152 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/158515) and [Reference 2](https://www.ibm.com/support/docview.wss?uid=ibm10888379).