First published: Thu Mar 16 2023(Updated: )
IBM Cloud Pak System does not invalidate session after logout which could allow a local user to impersonate another user on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak System | >=2.3.3.0<2.3.3.6 | |
IBM Cloud Pak System Software Suite | <=2.3.3.0 | |
IBM Cloud Pak System Software Suite | <=2.3.3.5 | |
<=2.3.3.0 - 2.3.3.5 | ||
<=2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4914.
The severity level of CVE-2020-4914 is medium with a CVSS score of 5.5.
The vulnerability allows a local user to impersonate another user on the system.
It is recommended to update to version 2.3.3.6 or later to fix the vulnerability.
You can find more information about CVE-2020-4914 at the following links: [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/191290), [IBM Support](https://www.ibm.com/support/pages/node/6967181), [CVE Details](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4914).