ZeroHour

CVE-2022-22318

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
Description

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Vendors
ibm
Products
curam social program management
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.