CVE-2023-26288 Information

Description

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

Reference

https://www.ibm.com/support/pages/node/7161538 https://exchange.xforce.ibmcloud.com/vulnerabilities/248477

Share on: