First published: Thu Apr 13 2023(Updated: )
IBM Cloud Pak System Suite session fixation
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak System | >=2.3.3.0<=2.3.3.5 | |
IBM Cloud Pak System | <=2.3.3.0 | |
IBM Cloud Pak System | <=2.3.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of IBM-XFORCE-191290 is high due to the potential for session fixation attacks allowing user impersonation.
To fix IBM-XFORCE-191290, ensure that your version of IBM Cloud Pak System Suite is updated to a version that invalidates sessions upon user logout.
IBM-XFORCE-191290 affects IBM Cloud Pak System Suite versions from 2.3.3.0 to 2.3.3.5.
The implication of IBM-XFORCE-191290 is that a local user could impersonate another user due to sessions not being invalidated appropriately.
Any user of IBM Cloud Pak System Suite versions 2.3.3.0 through 2.3.3.5 is at risk of being impacted by IBM-XFORCE-191290.