No advisories yet.
Solution
Principal Product and Version(s)Fix details 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4IBM strongly recommends addressing the vulnerability now by applying 1.3.8.5 (1.3.8-TIV-IOALA-FP5-sign) available from IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes . Refer to the README for upgrade instructions. For earlier than Log Analysis version 1.3.8.4, upgrade to Log Analysis 1.3.8.4.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7279877 |
|
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | |
| Title | IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change | |
| First Time appeared |
Ibm
Ibm operations Analytics Log Analysis |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.5.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.7.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.8.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm operations Analytics Log Analysis |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-30T19:22:14.290Z
Reserved: 2024-07-08T19:30:52.530Z
Link: CVE-2024-40683
No data.
No data.
No data.
OpenCVE Enrichment
No data.