Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1839

Опубликовано: 28 апр. 2011
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:rational_build_forge:7.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00253
Низкий

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

EPSS

Процентиль: 48%
0.00253
Низкий

5 Medium

CVSS2

Дефекты

CWE-200