CVE-2024-38315: IBM Aspera Shares session fixation
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Aspera Shares does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38315?
CVE-2024-38315 has been classified as a medium severity vulnerability due to the risk of user impersonation.
How do I fix CVE-2024-38315?
To fix CVE-2024-38315, ensure that you upgrade to a patched version of IBM Aspera Shares that addresses the session invalidation issue.
Who is affected by CVE-2024-38315?
IBM Aspera Shares versions from 1.0.0 to 1.10.0 PL3 are affected by CVE-2024-38315.
What does CVE-2024-38315 exploit?
CVE-2024-38315 exploits the failure to invalidate user sessions after a password reset, allowing impersonation of other users.
Is there a workaround for CVE-2024-38315?
As of now, there are no official workarounds for CVE-2024-38315 other than upgrading to a secure version.