ZeroHour

CVE-2016-0339

CVSS 3.0
5.6 medium
EPSS
1%p69
Published
()
Modified
Description

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."

Vendors
ibm
Products
security identity manager adapter
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.