CVE-2024-40683

Summary

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.

Affected Software

VendorProductVersion RangeStatus
IBMOperations Analytics - Log Analysis1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3affected
IBMOperations Analytics - Log Analysis1.3.6.0, 1.3.6.1affected
IBMOperations Analytics - Log Analysis1.3.7.0, 1.3.7.1, 1.3.7.2affected
IBMOperations Analytics - Log Analysis1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4affected

Weaknesses

  • CWE-613: CWE-613 Insufficient Session Expiration

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References