CVE-2019-4152

Publication date

2019-06-25 15:45:30

Family

ibm

State

PUBLISHED

Description

IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.