CVE-2024-25051

I

BM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.

References
Link Resource
https://www.ibm.com/support/pages/node/7229760 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:jazz_reporting_service:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_reporting_service:7.0.3:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

14 Jul 2025, 18:34

Type Values Removed Values Added
First Time Microsoft windows
Ibm jazz Reporting Service
Linux linux Kernel
Microsoft
Ibm
Linux
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_reporting_service:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_reporting_service:7.0.3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7229760 - () https://www.ibm.com/support/pages/node/7229760 - Vendor Advisory

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) IBM Jazz Reporting Service 7.0.2 y 7.0.3 no invalida la sesión después del inicio de sesión, lo que podría permitir que un usuario privilegiado autenticado se haga pasar por otro usuario en el sistema.

02 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 15:15

Updated : 2025-07-14 18:34


NVD link : CVE-2024-25051

Mitre link : CVE-2024-25051

CVE.ORG link : CVE-2024-25051


JSON object : View

CWE
CWE-613

Insufficient Session Expiration