Insufficient Session Expiration in IBM Cognos Analytics - CVE-2022-38707
Published: May 5, 2023
Vulnerability identifier: #VU75768
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38707
CWE-ID: CWE-613
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A local attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
Affected software
IBM Cognos Analytics
IBM Cognos Command Center
IBM Cognos Command Center
How to mitigate CVE-2022-38707
Install updates from vendor's website.
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17