VYPR
Critical severity9.8NVD Advisory· Published Jun 20, 2022· Updated Jun 17, 2026

CVE-2022-22318

CVE-2022-22318

Description

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Affected products

4
  • cpe:2.3:a:ibm:curam_social_program_management:8.0.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:curam_social_program_management:8.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:curam_social_program_management:8.0.1:*:*:*:*:*:*:*
    • (no CPE)range: 8.0.0, 8.0.1
    • (no CPE)range: 8.0.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.