PT-2020-18207 · Ibm · Ibm Cloud Pak For Security

Chris Shepherd

+7

·

Published

2020-11-30

·

Updated

2022-10-01

·

CVE-2020-4696

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Security version 1.3.0.1(CP4S)
Description The issue allows an authenticated user to obtain sensitive information from the previous session because the session is not properly invalidated after logout.
Recommendations For IBM Cloud Pak for Security version 1.3.0.1(CP4S), consider implementing a custom session invalidation mechanism after user logout as a temporary workaround until a patch is available.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2020-4696

Affected Products

Ibm Cloud Pak For Security