IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Sep 2024 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another user to obtain sensitive information. IBM X-Force ID: 233672. | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672. |
Thu, 12 Sep 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:*:*:*:*:*:*:*:* |
Tue, 13 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 Aug 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another user to obtain sensitive information. IBM X-Force ID: 233672. | |
Title | IBM Cloud Pak for Security session fixation | |
First Time appeared |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
Weaknesses | CWE-613 | |
CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_security:1.10.11.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.10.23.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2024-08-13T01:01:33.992Z
Updated: 2024-09-21T09:50:16.866Z
Reserved: 2022-08-16T18:42:49.431Z
Link: CVE-2022-38382
Vulnrichment
Updated: 2024-08-13T19:02:56.895Z
NVD
Status : Modified
Published: 2024-08-13T02:15:04.730
Modified: 2024-09-21T10:15:02.680
Link: CVE-2022-38382
Redhat
No data.