PT-2024-12907 · Ibm · Ibm Cognos Controller

Published

2024-05-03

·

Updated

2025-01-07

·

CVE-2023-40695

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 10.4.1 through 11.0.0
Description The issue allows an authenticated user to impersonate another user on the system because the session is not invalidated after logout.
Recommendations For versions 10.4.1 through 11.0.0, update to a version that includes a fix for this issue to prevent session impersonation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2023-40695

Affected Products

Ibm Cognos Controller