Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41845 | IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7164325 |
|
Fri, 09 Aug 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574. | |
| Title | IBM Aspera Shares session fixation | |
| First Time appeared |
Ibm
Ibm aspera Shares |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm aspera Shares |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-09T21:35:43.415Z
Reserved: 2023-07-11T17:33:12.813Z
Link: CVE-2023-38018
Updated: 2024-08-09T21:35:35.497Z
Status : Analyzed
Published: 2024-08-12T13:38:10.877
Modified: 2024-08-29T14:36:06.443
Link: CVE-2023-38018
No data.
OpenCVE Enrichment
No data.
EUVD