CVE-2024-25051

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7229760 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:jazz_reporting_service:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_reporting_service:7.0.3:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-02 15:15

Updated : 2025-07-14 18:34


NVD link : CVE-2024-25051

Mitre link : CVE-2024-25051

CVE.ORG link : CVE-2024-25051


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • jazz_reporting_service
CWE
CWE-613

Insufficient Session Expiration