IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21985736 | vendor advisory |
http://www.securityfocus.com/bid/91689 | vdb entry |
http://www.securitytracker.com/id/1036255 | vdb entry |