CVE-2016-0339

EUVD-2016-0374
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.6 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_identity_manager_adapter
7.0.0.0
ibmsecurity_identity_manager_adapter
7.0.0.1
ibmsecurity_identity_manager_adapter
7.0.0.2
ibmsecurity_identity_manager_adapter
7.0.0.3
ibmsecurity_identity_manager_adapter
7.0.1.0
ibmsecurity_identity_manager_adapter
7.0.1.1
𝑥
= Vulnerable software versions