Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92pj-cjhq-xw9c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-287