No analysis available yet.
Vendor Solution
Principal Product and Version(s)Fix details 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4IBM strongly recommends addressing the vulnerability now by applying 1.3.8.5 (1.3.8-TIV-IOALA-FP5-sign) available from IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes . Refer to the README for upgrade instructions. For earlier than Log Analysis version 1.3.8.4, upgrade to Log Analysis 1.3.8.4.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7279877 |
|
Thu, 30 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | |
| Title | IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change | |
| First Time appeared |
Ibm
Ibm operations Analytics Log Analysis |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.5.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.7.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.8.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm operations Analytics Log Analysis |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-30T19:22:14.290Z
Reserved: 2024-07-08T19:30:52.530Z
Link: CVE-2024-40683
Updated: 2026-07-30T19:22:10.356Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:00:18Z
-
CWE-613
Insufficient Session Expiration