
CVE-2024-43181 IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. https://www.cve.org/CVERecord?id=CVE-2024-43181
Post summary
The CVE reports that IBM Concert fails to invalidate sessions on logout, enabling authenticated users to impersonate other users.
