Описание
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:rational_license_key_server:8.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_license_key_server:8.1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_license_key_server:8.1.4.3:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00373
Низкий
2.1 Low
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.
EPSS
Процентиль: 59%
0.00373
Низкий
2.1 Low
CVSS2
Дефекты
CWE-264