Home
MEDIUM: 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
1.10.12.0 (semver)
affected
Default status
unaffected
1.10.0.0 (semver)
affected
Description
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.
Problem types
CWE-613 Insufficient Session Expiration
Product status
1.10.12.0 (semver)
1.10.0.0 (semver)
Credits
John Zuccato, Rodney Ryan, Chris Shepherd, Vince Dragnea, Ben Goodspeed, Dawid Bak
References
www.ibm.com/support/pages/node/7235432