CVE-2024-22358: IBM UrbanCode Deploy session fixation
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 280896.
Other sources
IBM UrbanCode Deploy (UCD) does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22358?
CVE-2024-22358 has a medium severity rating due to its potential to allow unauthorized session access.
How do I fix CVE-2024-22358?
To fix CVE-2024-22358, upgrade the affected IBM UrbanCode Deploy or IBM DevOps Deploy products to a version that includes the necessary security patches.
What versions of IBM UrbanCode Deploy are affected by CVE-2024-22358?
CVE-2024-22358 affects IBM UrbanCode Deploy versions 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, and 7.3 through 7.3.2.4.
Can authenticated users exploit CVE-2024-22358?
Yes, authenticated users can exploit CVE-2024-22358 to impersonate other users since sessions are not invalidated after logout.
Is CVE-2024-22358 applicable to IBM DevOps Deploy?
Yes, CVE-2024-22358 affects IBM DevOps Deploy versions up to 8.0.0.1.