Описание
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.0.0 (включая) до 10.0.9.2 (исключая)Версия от 10.0.0.0 (включая) до 10.0.9.1 (включая)Версия от 11.0 (включая) до 11.0.3 (исключая)Версия от 11.0.0.0 (включая) до 11.0.2 (включая)
Одно из
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00402
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-209
Связанные уязвимости
CVSS3: 5.3
github
2 месяца назад
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
EPSS
Процентиль: 34%
0.00402
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-209