PT-2024-27940 · Ibm · Ibm Aspera Shares

CVE-2024-38315

·

Published

2024-09-16

·

Updated

2024-09-20

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Aspera Shares versions 1.0 through 1.10.0 PL3
Description The issue allows an authenticated user to impersonate another user on the system because sessions are not invalidated after a password reset.
Recommendations For IBM Aspera Shares versions 1.0 through 1.10.0 PL3, upgrade to a newer version to mitigate the risk of remote exploit.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38315

Affected Products

Ibm Aspera Shares