SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2024-40683

MEDIUM · CVSS 6.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM Operations Analytics - Log Analysis versions 1.3.5.0 through 1.3.8.4 are vulnerable due to a failure to invalidate user sessions after a password change, potentially allowing an authenticated user to impersonate another user. This vulnerability poses a medium severity risk, as it could lead to unauthorized access and data breaches. Organizations using these specific versions should prioritize remediation to mitigate the risk of user impersonation and protect sensitive information.

CVE
CVE-2024-40683
Severity
MEDIUM
CVSS
6.3
EPSS
0.15%

Original NVD Description

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)