CVE-2018-1962: IBM Security Identity Manager

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.

Affected products

  • IBM Security Identity Manager: from 7.0.1, up to and including 7.0.1.10

Published 2019-02-04. Last modified 2026-06-17.