First published: Mon Jun 20 2022(Updated: )
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Curam Social Program Management | =8.0.0 | |
IBM Curam Social Program Management | =8.0.1 | |
HP HP-UX | ||
IBM AIX | ||
Ibm Z\/os | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22317 is critical, with a severity value of 9.8.
IBM Curam Social Program Management versions 8.0.0 and 8.0.1 are affected by CVE-2022-22317.
CVE-2022-22317 allows an authenticated user to impersonate another user on the system by not invalidating the session after logout.
No, HP-UX is not vulnerable to CVE-2022-22317.
More information about CVE-2022-22317 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/218281), [Link 2](https://www.ibm.com/support/pages/node/6596049)