Session Invalidation Vulnerability in IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2

Session Invalidation Vulnerability in IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2

CVE-2019-4439 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949.

Learn more about our Cloud Audit.