CVE-2013-2997

Publication date

2013-09-08 16:00:00

Family

ibm

State

PUBLISHED

Description

IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.