Session Management Flaw in IBM i2 Analyst's Notebook by IBM
CVE-2021-20431
4.3MEDIUM
Summary
IBM i2 Analyst's Notebook Premium versions 9.2.0, 9.2.1, and 9.2.2 contains a session management flaw that does not properly invalidate a user's session following logout. This flaw can allow an attacker to exploit the system, potentially accessing sensitive information even after a user has logged out. It is essential for users of affected versions to review their security practices and evaluate necessary updates to mitigate any risks associated with this vulnerability.
Affected Version(s)
i2 Analyst's Notebook Premium 9.2.0
i2 Analyst's Notebook Premium 9.2.1
i2 Analyst's Notebook Premium 9.2.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved