Skip to main content

Insufficient Session Expiration

CVE-2020-4914

Severity Medium
Score 4.2/10

Summary

IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.

  • LOW
  • LOCAL
  • LOW
  • UNCHANGED
  • NONE
  • HIGH
  • LOW
  • LOW

CWE-613 - Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

References

Advisory Timeline

  • Published