VYPR
Unrated severityNVD Advisory· Published Sep 16, 2024· Updated Sep 16, 2024

IBM Aspera Shares session fixation

CVE-2024-38315

Description

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.