First published: Tue Jul 23 2019(Updated: )
IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | =3.1.0 | |
IBM Cloud Private | =3.1.1 | |
IBM Cloud Private | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM Cloud Private is CVE-2019-4439.
The severity of CVE-2019-4439 is medium with a severity value of 5.3.
IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout.
The impact of CVE-2019-4439 is that a local user could impersonate another user on the system.
To fix CVE-2019-4439, update to a version of IBM Cloud Private that addresses this vulnerability.