Session Management Vulnerability in IBM Operations Analytics - Log Analysis
CVE-2024-40683

6.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 July 2026

What is CVE-2024-40683?

IBM Operations Analytics - Log Analysis experiences a significant session management flaw, where the system fails to invalidate user sessions after a password change. This vulnerability poses a substantial risk as it allows an authenticated user to potentially impersonate another user within the application, leading to unauthorized access to sensitive data and user privileges. Organizations using affected versions must address this security issue promptly to protect their systems and users.

Affected Version(s)

Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3

Operations Analytics - Log Analysis 1.3.6.0, 1.3.6.1

Operations Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.