CVE-2024-38315
16.09.2024, 15:15
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | aspera_shares | 1.0.0 ≤ 𝑥 < 1.10.0 |
ibm | aspera_shares | 1.10.0 |
ibm | aspera_shares | 1.10.0:patch_level1 |
ibm | aspera_shares | 1.10.0:patch_level2 |
ibm | aspera_shares | 1.10.0:patch_level3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration