Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4764-cw6v-4r4x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.

EPSS

Процентиль: 58%
0.0036
Низкий

5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5
nvd
около 9 лет назад

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.

EPSS

Процентиль: 58%
0.0036
Низкий

5 Medium

CVSS3

Дефекты

CWE-284