Description
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
CVSS breakdown
CVSS 3.0
Scope
Unchanged
User Interaction
None
Attack Vector
Network
Privileges Required
Low
Attack Complexity
Low
Integrity
Low
Confidentiality
Low
Availability
Low
E
Unchanged
RL
O
RC
Changed
Affected products
- ibm / Financial Transaction Manager3.0.2 – 3.0.2
- ibm / Financial Transaction Manager2.1.1 – 2.1.1
- ibm / Financial Transaction Manager3.1.0 – 3.1.0
- ibm / Financial Transaction Manager3.0.5 – 3.0.5
- ibm / Financial Transaction Manager3.0.6 – 3.0.6
- ibm / Financial Transaction Manager3.0.0 – 3.0.0
- ibm / Financial Transaction Manager3.2.2 – 3.2.2
- ibm / Financial Transaction Manager3.2.3 – 3.2.3
- ibm / Financial Transaction Manager3.2.4 – 3.2.4
References
- MISChttps://www.ibm.com/support/pages/node/6388702
- MISChttps://www.ibm.com/support/pages/node/6388744
- MISChttps://www.ibm.com/support/pages/node/6388708
- MISChttps://www.ibm.com/support/pages/node/6388706
- MISChttps://www.ibm.com/support/pages/node/6388704
- MISChttps://www.ibm.com/support/pages/node/6388722
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/183328