IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days