PT-2020-18046 · Ibm · Ibm Security Access Manager Appliance

Ammarit Thongthua

+2

·

Published

2020-10-14

·

Updated

2020-10-26

·

CVE-2020-4395

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager Appliance version 9.0.7
Description The issue allows an authenticated user to impersonate another user on the system because the session is not invalidated after logout.
Recommendations For IBM Security Access Manager Appliance version 9.0.7, consider implementing a workaround to manually invalidate sessions after logout until a patch is available. As a temporary mitigation measure, restrict access to sensitive areas of the system to minimize the risk of impersonation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4395

Affected Products

Ibm Security Access Manager Appliance