IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7164325 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-08-12 13:38
Updated : 2024-08-29 14:36
NVD link : CVE-2023-38018
Mitre link : CVE-2023-38018
CVE.ORG link : CVE-2023-38018
JSON object : View
Products Affected
ibm
- aspera_shares
CWE
CWE-384
Session Fixation