IBM Aspera Orchestrator 4.0.1 Password Change Vulnerability
CVE-2023-26288
5.5MEDIUM
Summary
IBM Aspera Orchestrator version 4.0.1 contains a security vulnerability related to its session management mechanism. Following a password change, the application does not invalidate user sessions, which could allow an authenticated user to impersonate another user on the system. This flaw creates potential for unauthorized access and may lead to sensitive information being exposed or abused. Users of this software should be aware of the implications of this oversight and take necessary precautions to mitigate potential risks.
Affected Version(s)
Aspera Orchestrator 4.0.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved