Impact
IBM Documentation Offline versions 1.0.0 through 1.4.1 contain a hard‑coded cryptographic key that can be exploited by a remote attacker to forge valid session tokens. This flaw permits the attacker to impersonate legitimate users, potentially leading to unauthorized data disclosure. Based on the description, it is inferred that if a forged session grants elevated privileges, the attacker could achieve remote code execution. The vulnerability is identified as CWE‑321, reflecting insecure key management.
Affected Systems
Vendors affected include IBM. The product IBM Documentation Offline, versions 1.0.0 to 1.4.1, is vulnerable to this session‑forging attack. IBM recommends upgrading to the latest release, 1.5.1, which removes the hard‑coded key and resolves the weakness.
Risk and Exploitability
The vulnerability carries a medium severity CVSS score of 5.3. EPSS information is not available, and the asset is not listed in the CISA KEV catalog. The attack vector is remote, as the compromised token can be forged over the network. While the likelihood of exploitation is uncertain due to the lack of EPSS data, the potential impact—particularly the inferred risk of remote code execution—warrants prompt remediation.
OpenCVE Enrichment