PT-2021-12233 · Ibm · Ibm Cloud Pak System
Published
2021-01-04
·
Updated
2021-07-21
·
CVE-2020-4919
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cloud Pak System version 2.3
Description
The issue is related to insufficient logout controls, which could allow an authenticated privileged user to impersonate another user on the system.
Recommendations
For IBM Cloud Pak System version 2.3, consider implementing additional logout controls or access restrictions to prevent user impersonation until a patch is available. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Cloud Pak System