First published: Wed Apr 23 2025(Updated: )
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Server | ||
IBM InfoSphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22351 is considered to have a moderate severity due to its impact on user session management.
You can fix CVE-2024-22351 by applying the recommended patch provided by IBM for InfoSphere Information Server 11.7.
CVE-2024-22351 may allow an authenticated user to impersonate another user, leading to unauthorized access to sensitive data.
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-22351.
CVE-2024-22351 affects IBM InfoSphere Information Server, specifically version 11.7 and earlier.