CVE-2021-20582: Infoleak
IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 199328.
Other sources
IBM Security Verify stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-20582.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Security Verify stores sensitive information in URL parameters. This may lead to information disclosure.'
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is 5.3, which is considered medium.
What are the affected software versions?
The affected software version is IBM Security Secret Server up to 11.0.
How can unauthorized parties gain access to the sensitive information?
Unauthorized parties can gain access to the sensitive information through server logs, referrer header, or browser history if they have access to the URLs.