CVE-2020-4395: Medium severity ibm security access manager vulnerability
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.
Other sources
IBM Security Access Manager does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4395?
The severity of CVE-2020-4395 is medium with a CVSS score of 6.3.
How does IBM Security Access Manager Appliance 9.0.7 handle session invalidation after logout?
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout.
What is the potential impact of CVE-2020-4395?
The potential impact of CVE-2020-4395 is that an authenticated user could impersonate another user on the system.
How can I fix CVE-2020-4395?
To fix CVE-2020-4395, update IBM Security Access Manager Appliance to a version that includes the fix for the session invalidation issue.
Where can I find more information about CVE-2020-4395?
You can find more information about CVE-2020-4395 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/179358) and the IBM support page (https://www.ibm.com/support/pages/node/6347592).