IBM Aspera Orchestrator 4.0.1 Password Change Vulnerability
CVE-2023-26288
5.5MEDIUM
What is CVE-2023-26288?
IBM Aspera Orchestrator version 4.0.1 contains a security vulnerability related to its session management mechanism. Following a password change, the application does not invalidate user sessions, which could allow an authenticated user to impersonate another user on the system. This flaw creates potential for unauthorized access and may lead to sensitive information being exposed or abused. Users of this software should be aware of the implications of this oversight and take necessary precautions to mitigate potential risks.
Affected Version(s)
Aspera Orchestrator 4.0.1