CVE-2020-4914: IBM Cloud Pak System Software Suite session fixation
IBM Cloud Pak System does not invalidate session after logout which could allow a local user to impersonate another user on the system.
Other sources
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.
IBM Cloud Pak System Suite session fixation
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-4914.
What is the severity level of CVE-2020-4914?
The severity level of CVE-2020-4914 is medium with a CVSS score of 5.5.
What is the impact of the IBM Cloud Pak System Suite session fixation vulnerability?
The vulnerability allows a local user to impersonate another user on the system.
How can I fix the IBM Cloud Pak System Suite session fixation vulnerability?
It is recommended to update to version 2.3.3.6 or later to fix the vulnerability.
Where can I find more information about CVE-2020-4914?
You can find more information about CVE-2020-4914 at the following links: [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/191290), [IBM Support](https://www.ibm.com/support/pages/node/6967181), [CVE Details](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4914).