CVE-2024-40683: IBM Operations Analytics - Log Analysis

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.

Affected products

  • IBM Operations Analytics - Log Analysis: from 1.3.5.0, up to and including 1.3.5.3; from 1.3.6.0, up to and including 1.3.6.1; from 1.3.7.0, up to and including 1.3.7.2; from 1.3.8.0, up to and including 1.3.8.4

Published 2026-07-30. Last modified 2026-10-02.