cbcvebase.
CVE-2019-4152
published 2019-06-25

CVE-2019-4152: IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow…

medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.

Affected

7 ranges
VendorProductVersion rangeFixed in
ibmsecurity_access_manager
ibmsecurity_access_manager
ibmsecurity_access_manager
ibmsecurity_access_manager
ibmsecurity_access_manager
ibmsecurity_access_manager
ibmsecurity_access_manager9.0.1 – 9.0.6