CVE-2018-1626: IBM Security Privileged Identity Manager
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.
Affected products
- IBM Security Privileged Identity Manager: version 2.1.1 only
Published 2019-04-02. Last modified 2026-06-17.