Technical Tip: JAZZ-208: Operator sessions are unable to expire
| Description | This article discusses JAZZ-208: Operator sessions are unable to expire. |
| Scope | FortiDLP. |
| Solution | Release Date: 9th July, 2019.
Overview: Operator sessions are kept alive by automatic polling of the Jazz Infrastructure API even when there is no user input.
Affected Products:
Unaffected Products:
Resolution: This issue has been fixed in Jazz Infrastructure version 5.0.3.
On-premises installations running an affected version are advised to upgrade at the earliest convenience. Releases are available to download through the Jazz Networks support portal.
A fix was deployed to the Jazz Cloud on 8th July 2019. Jazz Cloud customers do not need to take any additional action.
Vulnerability Information: Operator sessions on the following pages do not time out: #landing, #actions #cases/<id>, #admin/status, #forensics/user/<id>/passport/atlas, and #forensics/user/<id>/actions/atlas.
Acknowledgments: Issue found internally by Jazz Networks.
Disclosure Timeline:
|
