Session Management Vulnerability in IBM Operations Analytics - Log Analysis
CVE-2024-40683
6.3MEDIUM
What is CVE-2024-40683?
IBM Operations Analytics - Log Analysis experiences a significant session management flaw, where the system fails to invalidate user sessions after a password change. This vulnerability poses a substantial risk as it allows an authenticated user to potentially impersonate another user within the application, leading to unauthorized access to sensitive data and user privileges. Organizations using affected versions must address this security issue promptly to protect their systems and users.
Affected Version(s)
Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3
Operations Analytics - Log Analysis 1.3.6.0, 1.3.6.1
Operations Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2