PT-2019-16881 · Ibm · Ibm Tivoli Storage Productivity Center
CVE-2019-4072
·
Publicado
2019-05-09
·
Atualizado
2022-12-09
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Storage Productivity Center versions 5.2.1 through 5.2.17
Description
The issue allows users to remain idle within the application even after logging out, and by utilizing the application's back button, users can remain logged in for a short period. This presents users with information for the Spectrum Control Application.
Recommendations
For versions 5.2.1 through 5.2.17, consider implementing a timeout feature that automatically logs out users after a period of inactivity to prevent unauthorized access. Additionally, restrict the use of the back button to prevent users from accessing sensitive information after logging out.
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Tivoli Storage Productivity Center