IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.
History

Tue, 07 Jan 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm cognos Controller
CPEs cpe:2.3:a:ibm:cognos_controller:10.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:10.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Controller

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-02T18:38:51.283Z

Reserved: 2023-08-18T15:48:17.571Z

Link: CVE-2023-40695

cve-icon Vulnrichment

Updated: 2024-06-13T16:45:14.434Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-03T19:15:07.670

Modified: 2025-01-07T20:26:29.693

Link: CVE-2023-40695

cve-icon Redhat

No data.