IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openpages_grc_platform | Ibm | 7.1.0.0 (including) | 7.1.0.3 (including) |
Openpages_grc_platform | Ibm | 7.2.0.0 (including) | 7.2.0.2 (including) |
Openpages_grc_platform | Ibm | 7.3.0.0 (including) | 7.3.0.0 (including) |