6.3
CVE-2024-40683
- EPSS 0.15%
- Veröffentlicht 30.07.2026 18:11:56
- Zuletzt bearbeitet 02.10.2026 00:10:00
- Erkennungen
IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Operations Analytics - Log Analysis Version >= 1.3.5.0 <= 1.3.5.3
Ibm ≫ Operations Analytics - Log Analysis Version >= 1.3.6.0 <= 1.3.6.1
Ibm ≫ Operations Analytics - Log Analysis Version >= 1.3.7.0 <= 1.3.7.2
Ibm ≫ Operations Analytics - Log Analysis Version >= 1.3.8.0 <= 1.3.8.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://www.ibm.com/support/pages/node/7279877