Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=1 | vendor advisory |