CVE-2024-22351: IBM InfoSphere Information Server session fixation
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM InfoSphere Information Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22351?
CVE-2024-22351 is considered to have a moderate severity due to its impact on user session management.
How do I fix CVE-2024-22351?
You can fix CVE-2024-22351 by applying the recommended patch provided by IBM for InfoSphere Information Server 11.7.
What impact does CVE-2024-22351 have on my system?
CVE-2024-22351 may allow an authenticated user to impersonate another user, leading to unauthorized access to sensitive data.
Is there a known exploit for CVE-2024-22351?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-22351.
Which versions of IBM InfoSphere are affected by CVE-2024-22351?
CVE-2024-22351 affects IBM InfoSphere Information Server, specifically version 11.7 and earlier.