IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66642 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21689779 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/96179 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66645 | vendor advisory |