IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Guardium_data_encryption | Ibm | 3.0.0.2 (including) | 3.0.0.2 (including) |
Guardium_data_encryption | Ibm | 4.0.0.4 (including) | 4.0.0.4 (including) |