Session Management Flaw in IBM Jazz Foundation Products
CVE-2018-1492

4.3MEDIUM

Summary

The IBM Jazz Foundation products contain a vulnerability that allows a user with physical access to a system to log in as another user. This occurs because the server fails to properly terminate the previous session, potentially exposing sensitive information and user data. It is crucial for organizations using these products to ensure that systems are physically secure and implement best practices for session management to mitigate risks associated with this vulnerability.

Affected Version(s)

Rational Collaborative Lifecycle Management 5.0

Rational Collaborative Lifecycle Management 5.0.1

Rational Collaborative Lifecycle Management 5.0.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.