IBM Security Access Manager appliances store sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
CVE(s): CVE-2016-3045
Affected product(s) and affected version(s):
IBM Security Access Manager for Web 7.0 appliances, all firmware versions.
IBM Security Access Manager for Web 8.0 appliances, all firmware versions.
IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.
IBM Security Access Manager 9.0 appliances, all firmware versions.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2hxIl3m
X-Force Database: http://ift.tt/2hAxP8G
from IBM Product Security Incident Response Team http://ift.tt/2hxG2gU
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.