Medium severity4.4NVD Advisory· Published Jun 25, 2019· Updated Jun 17, 2026
CVE-2019-4152
CVE-2019-4152
Description
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:ibm:security_access_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:security_access_manager:*:*:*:*:*:*:*:*range: >=9.0.1,<=9.0.6
- (no CPE)range: 9.0.1
- Range: 9.0.1 - 9.0.6
Patches
Vulnerability mechanics
References
2- www.ibm.com/support/docview.wssnvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/158515nvdVDB EntryVendor Advisory
News mentions
0No linked articles in our index yet.