Session Management Flaw in IBM Content Navigator
CVE-2020-4253
6.3MEDIUM
What is CVE-2020-4253?
IBM Content Navigator 3.0CD exhibits a flaw where sessions are not invalidated after a user logs out. This oversight can potentially allow an authenticated user to impersonate another user by taking advantage of residual session data. The weakness poses a significant risk as it undermines the integrity of user sessions, leading to unauthorized access and potential data breaches. Addressing this vulnerability is crucial for ensuring the security and trustworthiness of user interactions within the system.
Affected Version(s)
Content Navigator 3.0CD