CVE-2024-38315

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*

History

20 Sep 2024, 14:09

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/294742 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/294742 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7168379 - () https://www.ibm.com/support/pages/node/7168379 - Vendor Advisory
CPE cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
Summary
  • (es) IBM Aspera Shares 1.0 a 1.10.0 PL3 no invalida la sesión después de un restablecimiento de contraseña, lo que podría permitir que un usuario autenticado se haga pasar por otro usuario en el sistema.
First Time Ibm
Ibm aspera Shares
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 6.5

16 Sep 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 15:15

Updated : 2024-09-20 14:09


NVD link : CVE-2024-38315

Mitre link : CVE-2024-38315

CVE.ORG link : CVE-2024-38315


JSON object : View

Products Affected

ibm

  • aspera_shares
CWE
CWE-613

Insufficient Session Expiration