Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22413 | IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7229760 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Wed, 02 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system. | |
| Title | IBM Jazz Reporting Service insufficient session expiration | |
| First Time appeared |
Ibm
Ibm jazz Reporting Service |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:jazz_reporting_service:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_reporting_service:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm jazz Reporting Service |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-02-26T18:29:01.345Z
Reserved: 2024-02-03T14:49:33.094Z
Link: CVE-2024-25051
Updated: 2025-04-02T15:12:17.860Z
Status : Analyzed
Published: 2025-04-02T15:15:56.370
Modified: 2025-07-14T18:34:13.800
Link: CVE-2024-25051
No data.
OpenCVE Enrichment
No data.
EUVD