Session Management Vulnerability in IBM Jazz Reporting Service
CVE-2024-25051

6.6MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 April 2025

Summary

The IBM Jazz Reporting Service versions 7.0.2 and 7.0.3 fail to properly invalidate user sessions upon logout. This oversight may allow an authenticated privileged user to maintain access, leading to potential impersonation of other users within the system. It is crucial for users to be aware of this issue to safeguard against unauthorized access and ensure that session controls are effectively enforced post-logout.

Affected Version(s)

Jazz Reporting Service 7.0.2, 7.0.3

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.