The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days