PT-2024-27940 · Ibm · Ibm Aspera Shares

Published

2024-09-16

·

Updated

2024-09-20

·

CVE-2024-38315

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Aspera Shares versions 1.0 through 1.10.0 PL3
Description The issue allows an authenticated user to impersonate another user on the system because sessions are not invalidated after a password reset.
Recommendations For IBM Aspera Shares versions 1.0 through 1.10.0 PL3, upgrade to a newer version to mitigate the risk of remote exploit.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-38315

Affected Products

Ibm Aspera Shares