Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rqr-xfwj-w2q9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.

EPSS

Процентиль: 9%
0.00033
Низкий

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 4.4
nvd
около 5 лет назад

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.

EPSS

Процентиль: 9%
0.00033
Низкий

Дефекты

CWE-384