First published: Thu Jul 11 2019(Updated: )
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-force ID: 159032.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | >=1.1.3<=1.1.3.2 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-4193.
The severity level of CVE-2019-4193 is high with a CVSS score of 7.5.
IBM Jazz for Service Management versions 1.1.3 and 1.1.3.2 are affected by CVE-2019-4193.
CVE-2019-4193 may lead to information disclosure if unauthorized parties have access to the URLs hosting sensitive information.
To fix CVE-2019-4193, it is recommended to apply the necessary updates or patches provided by IBM.