CVE-2013-2997: IBM Security Appscan

Low severity, CVSS 1.7. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.

Affected products

  • IBM Security Appscan: up to and including 8.6.0.2; version 5.6.0.0 only; version 6.0.0.0 only; version 6.0.1.0 only; version 6.0.2.0 only; version 6.1.1.0 only; …

Published 2013-09-08. Last modified 2026-06-16.