Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf7x-r4m4-rqc9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.

IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.

EPSS

Процентиль: 39%
0.00177
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость системы автоматизации деятельности предприятия IBM Business Process Manager и программного средства автоматизации цифровых процессов IBM Business Automation Workflow, связанная с ошибками разграничения доступа, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 39%
0.00177
Низкий

Дефекты

CWE-200