CVE-2024-22351Insufficient Session Expiration in IBM Infosphere Information Server

Severity
6.3MEDIUMNVD
EPSS
0.1%
top 64.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateApr 24

Description

IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-79gg-w7m7-c3gc: IBM InfoSphere Information 112025-04-24
CVEList
IBM InfoSphere Information Server session fixation2025-04-23
CVE-2024-22351 — Insufficient Session Expiration in IBM | cvebase