PT-2022-15356 · Ibm · Ibm Curam Social Program Management

Published

2022-06-20

·

Updated

2022-06-28

·

CVE-2022-22317

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Curam Social Program Management versions 8.0.0 through 8.0.1
Description The issue allows an authenticated user to impersonate another user on the system because the session is not invalidated after logout.
Recommendations For versions 8.0.0 and 8.0.1, consider implementing a custom session invalidation mechanism after user logout as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22317

Affected Products

Ibm Curam Social Program Management