CVE-2021-20431: Medium severity IBM i2 Analyst's Notebook Premium vulnerability
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.
Other sources
IBM i2 Analyst's Notebook Premium does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20431?
The CVE-2021-20431 vulnerability is classified as a medium severity issue due to its potential to expose sensitive information.
How do I fix CVE-2021-20431?
To remediate CVE-2021-20431, ensure that you update IBM i2 Analyst's Notebook Premium to the latest version where session invalidation after logout is properly implemented.
Which versions of IBM i2 Analyst's Notebook Premium are affected by CVE-2021-20431?
CVE-2021-20431 affects IBM i2 Analyst's Notebook Premium versions 9.2.0, 9.2.1, and 9.2.2.
Is my data at risk with CVE-2021-20431?
Yes, CVE-2021-20431 poses a risk as it allows attackers to potentially access sensitive information from a session that has not been properly invalidated after logout.
What is the nature of the vulnerability described in CVE-2021-20431?
CVE-2021-20431 is a session management vulnerability that fails to invalidate a user's session after logout, leading to potential information leakage.