Atlas eDiscovery Process Management has addressed vulnerability due to sensitive information stored in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
CVE(s): CVE-2017-1355
Affected product(s) and affected version(s):
Atlas eDiscovery Process Management 6.0.3 – 6.0.3.5
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2i4e8Yq
X-Force Database: http://ift.tt/2jzcJd1
The post IBM Security Bulletin: IBM Atlas eDiscovery Process Management affected by vulnerability due to sensitive information stored in URL parameters. appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2i2u2mj
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.