PT-2019-16881 · Ibm · Ibm Tivoli Storage Productivity Center

Published

2019-05-09

·

Updated

2022-12-09

·

CVE-2019-4072

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Tivoli Storage Productivity Center versions 5.2.1 through 5.2.17
Description The issue allows users to remain idle within the application even after logging out, and by utilizing the application's back button, users can remain logged in for a short period. This presents users with information for the Spectrum Control Application.
Recommendations For versions 5.2.1 through 5.2.17, consider implementing a timeout feature that automatically logs out users after a period of inactivity to prevent unauthorized access. Additionally, restrict the use of the back button to prevent users from accessing sensitive information after logging out.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2019-4072

Affected Products

Ibm Tivoli Storage Productivity Center