Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23v6-7r6w-c9x5

Опубликовано: 20 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

EPSS

Процентиль: 4%
0.00018
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.9
nvd
29 дней назад

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

EPSS

Процентиль: 4%
0.00018
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327