IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.Referenceshttps://www.ibm.com/support/pages/node/7161538https://exchange.xforce.ibmcloud.com/vulnerabilities/248477