PT-2019-16881 · Ibm · Ibm Tivoli Storage Productivity Center
Published
2019-05-09
·
Updated
2022-12-09
·
CVE-2019-4072
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Storage Productivity Center versions 5.2.1 through 5.2.17
Description
The issue allows users to remain idle within the application even after logging out, and by utilizing the application's back button, users can remain logged in for a short period. This presents users with information for the Spectrum Control Application.
Recommendations
For versions 5.2.1 through 5.2.17, consider implementing a timeout feature that automatically logs out users after a period of inactivity to prevent unauthorized access. Additionally, restrict the use of the back button to prevent users from accessing sensitive information after logging out.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Storage Productivity Center