PT-2020-18046 · Ibm · Ibm Security Access Manager Appliance
Ammarit Thongthua
+2
·
Published
2020-10-14
·
Updated
2020-10-26
·
CVE-2020-4395
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Access Manager Appliance version 9.0.7
Description
The issue allows an authenticated user to impersonate another user on the system because the session is not invalidated after logout.
Recommendations
For IBM Security Access Manager Appliance version 9.0.7, consider implementing a workaround to manually invalidate sessions after logout until a patch is available. As a temporary mitigation measure, restrict access to sensitive areas of the system to minimize the risk of impersonation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Access Manager Appliance