CVE-2023-45187
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 9, 2024
Updated: Feb 15, 2024
CWE ID 613
Summary
CVE-2023-45187 affects versions 7.0.2 and 7.0.3 of IBM Engineering Lifecycle Optimization - Publishing. This vulnerability allows an authenticated user to maintain their session and potentially impersonate another user after logging out. IBM X-Force has assigned ID 268749 to this issue. The failure to invalidate sessions upon logout poses a significant security risk, enabling unauthorized access and potential data breaches. IBM urges users to apply the necessary patches to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- IBM Corporation