CVE-2024-38315

Publication date

2024-09-16 15:05:49

Family

ibm

State

PUBLISHED

Description

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.