CVE-2024-25051: IBM Jazz Reporting Service insufficient session expiration
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
Other sources
IBM Jazz Reporting Service does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25051?
CVE-2024-25051 has a high severity rating due to the potential for user impersonation after logout.
How do I fix CVE-2024-25051?
To fix CVE-2024-25051, apply the latest patches provided by IBM for Jazz Reporting Service.
What versions of IBM Jazz Reporting Service are affected by CVE-2024-25051?
CVE-2024-25051 affects IBM Jazz Reporting Service version 7.0.2 and 7.0.3.
What is the impact of not addressing CVE-2024-25051?
Failing to address CVE-2024-25051 may allow an authenticated privileged user to impersonate other users.
Is user session invalidation important regarding CVE-2024-25051?
Yes, proper session invalidation is crucial to prevent unauthorized access and impersonation vulnerabilities like CVE-2024-25051.