CVE-2020-4995: Medium severity ibm security identity governance and intelligence vulnerability
IBM Security Access Manager does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session.
Other sources
IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4995.
What is the severity rating of CVE-2020-4995?
The severity rating of CVE-2020-4995 is medium with a value of 5.3.
Which software is affected by CVE-2020-4995?
IBM Security Identity Governance and Intelligence version 5.2.6 is affected by CVE-2020-4995.
What is the impact of CVE-2020-4995?
CVE-2020-4995 could allow a user to obtain sensitive information from another user's session.
Are there any references for CVE-2020-4995?
Yes, you can find references for CVE-2020-4995 at the following URLs: [https://exchange.xforce.ibmcloud.com/vulnerabilities/192912](https://exchange.xforce.ibmcloud.com/vulnerabilities/192912) and [https://www.ibm.com/support/pages/node/6413393](https://www.ibm.com/support/pages/node/6413393).