CVE-2022-38382: IBM Cloud Pak for Security session fixation
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.
Other sources
IBM Cloud Pak for Security (CP4S) does not invalidate session after logout which could allow another user to impersonate another user on the system and obtain sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38382?
CVE-2022-38382 has been rated as a medium severity vulnerability due to improper session management.
How do I fix CVE-2022-38382?
To fix CVE-2022-38382, upgrade to IBM Cloud Pak for Security version 1.10.12.0 or later and IBM QRadar Suite Software version 1.10.24.0 or later.
What impact does CVE-2022-38382 have on affected systems?
CVE-2022-38382 allows another authenticated user to access session data after logout, leading to potential unauthorized access to sensitive information.
Which versions are affected by CVE-2022-38382?
CVE-2022-38382 affects IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 to 1.10.23.0.
Is there a public reference for CVE-2022-38382?
Yes, CVE-2022-38382 has detailed information available through IBM's support and X-Force Exchange.