CVE-2023-45187: IBM Engineering Lifecycle Optimization - Publishing session fixation
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.
Other sources
IBM Engineering Lifecycle Optimization - Publishing does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45187?
CVE-2023-45187 is classified as a medium severity vulnerability.
How do I fix CVE-2023-45187?
To fix CVE-2023-45187, upgrade to IBM Engineering Lifecycle Optimization - Publishing versions 7.0.4 or later.
What is the impact of CVE-2023-45187?
The impact of CVE-2023-45187 allows an authenticated user to impersonate another user due to session management flaws.
Which versions of IBM Pub are affected by CVE-2023-45187?
CVE-2023-45187 affects IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3.
Is there a workaround for CVE-2023-45187?
Currently, there are no documented workarounds for CVE-2023-45187, and upgrading to a newer version is recommended.