IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2019-06-25T15:45:30.018496Z

Updated: 2024-09-16T19:10:50.464Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-4152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-06-25T16:15:10.570

Modified: 2023-02-03T20:28:26.953

Link: CVE-2019-4152

cve-icon Redhat

No data.