IBM Cloud Automation Manager will redirect when a bad API path is requested rather than issuing a 404. User may expect an error but be redirected to a home page instead.
CVE(s): CVE-2019-4132
Affected product(s) and affected version(s):
IBM Cloud Automation Manager 3.1.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10967477
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158274
The post IBM Security Bulletin: IBM Cloud Automation Manager is affected by a forbidden resouce redirect for bad API path CVE-2019-4132 appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2HnH3nv
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.