CVE-2022-41291: Medium severity IBM InfoSphere Information Server vulnerability
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
Other sources
IBM InfoSphere Information Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-41291?
CVE-2022-41291 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows an authenticated user to impersonate another user on the system due to not invalidating the session after logout.
How severe is CVE-2022-41291?
CVE-2022-41291 has a severity rating of 6.5, which is classified as medium severity.
Which systems are affected by CVE-2022-41291?
IBM InfoSphere Information Server 11.7 is affected by CVE-2022-41291.
How can I fix CVE-2022-41291?
To fix CVE-2022-41291, you should apply the patch provided by IBM, which can be found at [https://www.ibm.com/support/docview.wss?uid=ibm10878310](https://www.ibm.com/support/docview.wss?uid=ibm10878310).
Is IBM AIX affected by CVE-2022-41291?
No, IBM AIX is not vulnerable to CVE-2022-41291.