IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21640352 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84066 | vdb entry |