ibm security-privileged-identity-manager CVE-2018-1626 is a vulnerability in IBM Security Privileged Identity Manager
Published on April 2, 2019

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.

NVD


Products Associated with CVE-2018-1626

Want to know whenever a new CVE is published for IBM Security Privileged Identity Manager? stack.watch will email you.

 

Affected Versions

IBM Security Privileged Identity Manager Version 2.1.1 is affected by CVE-2018-1626

Exploit Probability

EPSS
0.19%
Percentile
40.76%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.