Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32xw-6g8c-rxjj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

EPSS

Процентиль: 49%
0.0026
Низкий

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.4
nvd
около 5 лет назад

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

EPSS

Процентиль: 49%
0.0026
Низкий

Дефекты

CWE-384