CVE Vulnerabilities

CVE-2022-38382

Insufficient Session Expiration

Published: Aug 13, 2024 | Modified: Sep 21, 2024
CVSS 3.x
4.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Cloud_pak_for_security Ibm 1.10.0.0 (including) 1.10.11.0 (including)
Qradar_suite Ibm 1.10.12.0 (including) 1.10.23.0 (including)

Potential Mitigations

References