does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now. Product(s)Version(s)Remediation/Fix/InstructionsTransformation Extender Advanced10.0.x 10.0.1.11 https://www.ibm.com/support/fixcentral/swg/selectFixes Transformation Extender Advanced10.0.x 10.0.2.0 https://www.ibm.com/support/fixcentral/swg/selectFixes
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7246882 |
|
Wed, 01 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Title | IBM Transformation Extender Advanced session fixation | |
| First Time appeared |
Ibm
Ibm transformation Extender Advanced |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:transformation_extender_advanced:10.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm transformation Extender Advanced |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-10-01T17:20:31.354Z
Reserved: 2023-12-01T01:47:32.863Z
Link: CVE-2023-49881
Updated: 2025-10-01T17:20:27.389Z
Status : Analyzed
Published: 2025-10-01T17:15:37.367
Modified: 2025-10-03T17:38:09.453
Link: CVE-2023-49881
No data.
OpenCVE Enrichment
No data.