IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6414777 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/196191 | vdb entry vendor advisory |