First published: Thu Oct 08 2020(Updated: )
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager Appliance | =9.0.7 | |
<=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4395 is medium with a CVSS score of 6.3.
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout.
The potential impact of CVE-2020-4395 is that an authenticated user could impersonate another user on the system.
To fix CVE-2020-4395, update IBM Security Access Manager Appliance to a version that includes the fix for the session invalidation issue.
You can find more information about CVE-2020-4395 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/179358) and the IBM support page (https://www.ibm.com/support/pages/node/6347592).