Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vmw6-43v5-r7vm

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.

EPSS

Процентиль: 23%
0.00077
Низкий

Связанные уязвимости

nvd
больше 17 лет назад

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.

EPSS

Процентиль: 23%
0.00077
Низкий