CVE-2023-46158Insufficient Session Expiration in IBM Websphere Application Server Liberty

Severity
9.8CRITICALNVD
CNA4.9
EPSS
0.0%
top 87.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25

Description

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/websphere_application_server_liberty23.0.0.9, 23.0.0.10
NVDibm/websphere_application23.0.0.923.0.0.11

🔴Vulnerability Details

2
CVEList
IBM WebSphere Application Server session fixation2023-10-25
GHSA
GHSA-3942-82qw-f9qh: IBM WebSphere Application Server Liberty 232023-10-25
CVE-2023-46158 — Insufficient Session Expiration in IBM | cvebase