IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/140977 | third party advisory vdb entry |
http://www.ibm.com/support/docview.wss?uid=ibm10716599 | vendor advisory |