IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102016 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/126682 | Issue Tracking VDB Entry Vendor Advisory |
https://www.ibm.com/support/docview.wss?uid=swg22005836 | Issue Tracking Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2017-07-14T00:00:00
Updated: 2017-12-08T10:57:01
Reserved: 2016-11-30T00:00:00
Link: CVE-2017-1355
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-12-07T15:29:00.830
Modified: 2017-12-19T13:36:40.807
Link: CVE-2017-1355
JSON object: View
Redhat Information
No data.
CWE