CVE-2016-0339
—CVSS 3.0
5.6 medium
EPSS
1%p69
Published
()
Modified
Description
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
- Vendors
- ibm
- Products
- security identity manager adapter
- Weakness
- CWE-284
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.