CVE-2022-22318
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected (2)
Products: Ibm: Curam Social Program Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.0 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | All versions |
Ibm Aix | All versions |
Ibm Z/os | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Oracle Solaris | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.