Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqv6-xxj9-p7wp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

EPSS

Процентиль: 55%
0.00327
Низкий

Связанные уязвимости

nvd
больше 14 лет назад

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

EPSS

Процентиль: 55%
0.00327
Низкий