Junglewise Threat Intelligence

CVE-2024-40683: IBM Operations Analytics - Log Analysis insufficient session expiration

CVE-2024-40683 · Severity: medium · CVSS 6.3 · Published 2026-07-30

Executive brief

IBM Operations Analytics - Log Analysis, a tool used for monitoring and analyzing IT infrastructure logs, contains a security flaw where user sessions remain active even after a password has been changed. This could allow an unauthorized person who has gained access to a session to continue using the system as that user, even if the legitimate owner attempts to lock them out by updating their credentials. This poses a risk of unauthorized data access or system manipulation by impersonating legitimate users.

Technical details

IBM Operations Analytics - Log Analysis is vulnerable to insufficient session expiration (CWE-613) due to a Time-Of-Check to Time-Of-Use (TOCTOU) weakness in its built-in user password management feature. The application fails to terminate or invalidate existing authenticated sessions when a user's password is updated. An authenticated attacker with access to a valid session token can maintain access to the system and impersonate the user even after the user has changed their credentials. This vulnerability affects the built-in authentication module and can be remediated by upgrading to version 1.3.8.5.

Affected products

  • IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4

Timeline

  • 2026-07-13: advisory: Initial publication by IBM
  • 2026-07-30: disclosed: NVD publication date

References

Related threats