First published: Mon Aug 12 2024(Updated: )
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite | <=1.10.12.0 - 1.10.23.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite Software | >=1.10.12.0<=1.10.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38382 has been rated as a medium severity vulnerability due to improper session management.
To fix CVE-2022-38382, upgrade to IBM Cloud Pak for Security version 1.10.12.0 or later and IBM QRadar Suite Software version 1.10.24.0 or later.
CVE-2022-38382 allows another authenticated user to access session data after logout, leading to potential unauthorized access to sensitive information.
CVE-2022-38382 affects IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 to 1.10.23.0.
Yes, CVE-2022-38382 has detailed information available through IBM's support and X-Force Exchange.