CVE-2015-1984: Infoleak
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1984?
CVE-2015-1984 has a medium severity, allowing remote authenticated users to bypass access restrictions.
How do I fix CVE-2015-1984?
To mitigate CVE-2015-1984, apply the latest fix pack or update provided by IBM for the affected versions.
Which versions of IBM InfoSphere Master Data Management are affected by CVE-2015-1984?
CVE-2015-1984 affects IBM InfoSphere Master Data Management versions 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03.
What are the potential risks associated with CVE-2015-1984?
CVE-2015-1984 could lead to unauthorized access to user profiles, increasing the risk of targeted brute-force attacks.
Is CVE-2015-1984 a newly discovered vulnerability?
No, CVE-2015-1984 was publicly disclosed in 2015.