Description
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.
Published: 2026-07-30
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a Time‑of‑Check to Time‑of‑Use weakness that causes authenticated user sessions to remain valid after a password change. Identified as CWE‑613, this defect allows an attacker who has legitimate access to continue using the same session and therefore impersonate the user or other system users without reauthentication. Consequently, confidential actions or data could be accessed by an individual who has not correctly logged in.

Affected Systems

IBM Operations Analytics – Log Analysis, versions 1.3.5.0 through 1.3.8.4, inclusive of all intermediate releases.

Risk and Exploitability

The CVSS v3.1 score is 6.3, indicating a medium severity, while the EPSS score is below 1%, implying a low probability of widespread exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated session and a password change event; the attacker must retain or steal the session token, after which the session will not be invalidated as it should be. While there is no remote code execution vector, the ability to impersonate a user after a password change poses a significant privilege escalation risk within the affected environment.

Generated by OpenCVE AI on August 2, 2026 at 05:01 UTC.

Remediation

Vendor Solution

Principal Product and Version(s)Fix details 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4IBM strongly recommends addressing the vulnerability now by applying 1.3.8.5 (1.3.8-TIV-IOALA-FP5-sign) available from IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes . Refer to the README for upgrade instructions. For earlier than Log Analysis version 1.3.8.4, upgrade to Log Analysis 1.3.8.4.


OpenCVE Recommended Actions

  • Upgrade IBM Operations Analytics – Log Analysis to version 1.3.8.5 (or, for earlier installations, to 1.3.8.4) via IBM Fix Central using the README for upgrade instructions.
  • Verify that the application invalidates all active session tokens immediately after a password change by testing a password reset and confirming that the previous session cookie or token is no longer accepted.
  • Configure the system to terminate all user sessions upon a password change or enforce a re-authentication requirement; if the application does not support this natively, enforce it through a custom middleware or access‑control rule.
  • Monitor authentication and session logs for indicators of sustained session activity after password changes; establish alerts to flag anomalous persistence and review them promptly.

Generated by OpenCVE AI on August 2, 2026 at 05:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm operations Analytics - Log Analysis
CPEs cpe:2.3:a:ibm:operations_analytics_-_log_analysis:*:*:*:*:*:*:*:*
Vendors & Products Ibm operations Analytics - Log Analysis

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.
Title IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change
First Time appeared Ibm
Ibm operations Analytics Log Analysis
Weaknesses CWE-613
CPEs cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.8.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm operations Analytics Log Analysis
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm Operations Analytics - Log Analysis Operations Analytics Log Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T19:22:14.290Z

Reserved: 2024-07-08T19:30:52.530Z

Link: CVE-2024-40683

cve-icon Vulnrichment

Updated: 2026-07-30T19:22:10.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:16:57.767

Modified: 2026-08-12T18:42:36.057

Link: CVE-2024-40683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:15:15Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration