Home

Description

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.

PUBLISHED Reserved 2023-12-16 | Published 2024-02-02 | Updated 2024-08-02 | Assigner ibm




MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Problem types

CWE-384 Session Fixation

Product status

Default status
unaffected

1.3, 2.0, 2.1
affected

References

www.ibm.com/support/pages/node/7113759 vendor-advisory

exchange.xforce.ibmcloud.com/vulnerabilities/275131 vdb-entry

cve.org (CVE-2023-50941)

nvd.nist.gov (CVE-2023-50941)

Download JSON