Session Management Flaw in IBM Content Navigator
CVE-2020-4253

6.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 March 2020

Summary

IBM Content Navigator 3.0CD exhibits a flaw where sessions are not invalidated after a user logs out. This oversight can potentially allow an authenticated user to impersonate another user by taking advantage of residual session data. The weakness poses a significant risk as it undermines the integrity of user sessions, leading to unauthorized access and potential data breaches. Addressing this vulnerability is crucial for ensuring the security and trustworthiness of user interactions within the system.

Affected Version(s)

Content Navigator 3.0CD

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.