Insufficient Session Expiration in Watson Query on Cloud Pak for Data and Db2 Big SQL - CVE-2024-35160
Published: December 2, 2024 / Updated: April 22, 2026
Vulnerability identifier: #VU101083
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35160
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
Affected software
Watson Query on Cloud Pak for Data
Db2 Big SQL
Db2 Big SQL
How to mitigate CVE-2024-35160
Install updates from vendor's website.
Watson Query on Cloud Pak for Data - addressed in versions 4.8.8, 5.0.0
Db2 Big SQL - update to 7.7.0
Db2 Big SQL - update to 7.7.0