Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r9r-8crm-q8p5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
около 7 лет назад

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3