CVE-2022-40228Insufficient Session Expiration in IBM Datapower Gateway

Severity
5.4MEDIUMNVD
CNA3.7
EPSS
0.1%
top 81.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22

Description

IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235527.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5ibm/datapower_gateway10.0.3.010.0.4.0+3
NVDibm/datapower_gateway10.0.1.010.0.1.9+3

🔴Vulnerability Details

2
GHSA
GHSA-52gh-q32v-jm2r: IBM DataPower Gateway 102022-11-22
CVEList
IBM DataPower Gateway session fixation2022-11-22
CVE-2022-40228 — Insufficient Session Expiration in IBM | cvebase