Session Management Flaw in IBM Content Navigator
CVE-2020-4253
6.3MEDIUM
Summary
IBM Content Navigator 3.0CD exhibits a flaw where sessions are not invalidated after a user logs out. This oversight can potentially allow an authenticated user to impersonate another user by taking advantage of residual session data. The weakness poses a significant risk as it undermines the integrity of user sessions, leading to unauthorized access and potential data breaches. Addressing this vulnerability is crucial for ensuring the security and trustworthiness of user interactions within the system.
Affected Version(s)
Content Navigator 3.0CD
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved