← Vulnerability feed

Vulnerability record · CVE-2023-45187 · published 9 February 2024

CVE-2023-45187: Ibm engineering lifecycle optimization insufficient session expiration vulnerability

Ibm · Engineering Lifecycle Optimization

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.

8.8 CVSS 3.1 High EPSS 0.38% · top 70.5% CWE-613 · Insufficient session expiration
8.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45187 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-29844Ibm engineering lifecycle optimization server-side request forgery (ssrf) vulnerabilityIBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…EPSS 0.59%7.5CVE-2023-45191Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerabilityIBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…EPSS 0.66%7.5CVE-2021-29774Ibm engineering lifecycle optimization vulnerabilityIBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.EPSS 0.98%6.5CVE-2021-29786Ibm engineering lifecycle optimization cleartext storage of sensitive data vulnerabilityIBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.EPSS 0.56%6.1CVE-2024-52890Ibm engineering lifecycle optimization vulnerabilityIBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.EPSS 0.18%6.1CVE-2023-45190Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerabilityIBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea…EPSS 0.26%5.4CVE-2021-29673Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%5.4CVE-2021-29713Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2023-45187), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.