First published: Tue Jul 10 2018(Updated: )
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | >=5.2.0<=5.2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1367 is rated as a high severity vulnerability due to potential sensitive information disclosure.
To resolve CVE-2017-1367, you should upgrade to a version of IBM Security Identity Governance and Intelligence later than 5.2.3.2.
CVE-2017-1367 can lead to the disclosure of sensitive information included in URL parameters.
CVE-2017-1367 affects users running IBM Security Identity Governance and Intelligence Virtual Appliance versions 5.2 through 5.2.3.2.
Attackers may gain access to sensitive information if they can view server logs, referrer headers, or browser history containing the vulnerable URLs.