CVE-2019-4562: Infoleak
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.
Other sources
IBM Security Directory Server stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-4562.
What is the title of this vulnerability?
The title of this vulnerability is "IBM Security Directory Server stores sensitive information in URLs."
What is the severity rating of CVE-2019-4562?
The severity rating of CVE-2019-4562 is medium, with a severity value of 5.3.
How does IBM Security Directory Server store sensitive information in URLs?
IBM Security Directory Server 6.4.0 stores sensitive information in URLs, which can lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header, or browser history.
What is the affected software version range for this vulnerability?
The affected software version range for this vulnerability is from 6.4.0.0 to 6.4.0.20.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-200.
How can unauthorized parties access the sensitive information in URLs?
Unauthorized parties can access the sensitive information in URLs through server logs, referer header, or browser history.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following links: [https://exchange.xforce.ibmcloud.com/vulnerabilities/166623](https://exchange.xforce.ibmcloud.com/vulnerabilities/166623) and [https://www.ibm.com/support/pages/node/1288660](https://www.ibm.com/support/pages/node/1288660).