First published: Thu Jul 29 2021(Updated: )
IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 199328.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Secret Server | <11.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-20582.
The title of this vulnerability is 'IBM Security Verify stores sensitive information in URL parameters. This may lead to information disclosure.'
The severity rating for this vulnerability is 5.3, which is considered medium.
The affected software version is IBM Security Secret Server up to 11.0.
Unauthorized parties can gain access to the sensitive information through server logs, referrer header, or browser history if they have access to the URLs.