IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.

Project Subscriptions

Vendors Products
Operations Analytics Log Analysis Subscribe
Advisories

No advisories yet.

Fixes

Solution

Principal Product and Version(s)Fix details 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4IBM strongly recommends addressing the vulnerability now by applying 1.3.8.5 (1.3.8-TIV-IOALA-FP5-sign) available from IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes . Refer to the README for upgrade instructions. For earlier than Log Analysis version 1.3.8.4, upgrade to Log Analysis 1.3.8.4.


Workaround

No workaround given by the vendor.

History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system.
Title IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change
First Time appeared Ibm
Ibm operations Analytics Log Analysis
Weaknesses CWE-613
CPEs cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_log_analysis:1.3.8.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm operations Analytics Log Analysis
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T19:22:14.290Z

Reserved: 2024-07-08T19:30:52.530Z

Link: CVE-2024-40683

cve-icon Vulnrichment

Updated: 2026-07-30T19:22:10.356Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:18Z

Weaknesses