What the vulnerability does
01Description
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
CVSS base score
CVSS vector
CVSS:3.0/I:L/A:L/AC:L/UI:N/PR:L/C:L/AV:N/S:U/RL:O/E:U/RC:C
What the vulnerability does
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
Key dates
External resources