PT-2019-17060 · Ibm · Ibm Cloud Orchestrator+1

Publicado

2019-10-24

·

Atualizado

2019-10-30

·

CVE-2019-4397

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise versions 2.4 through 2.4.0.5 IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise versions 2.5 through 2.5.0.9
Description The issue concerns the storage of sensitive information in URL parameters, which may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Recommendations For versions 2.4 through 2.4.0.5, consider restricting access to server logs and referrer headers to minimize the risk of exploitation. For versions 2.5 through 2.5.0.9, consider implementing measures to protect sensitive information in URL parameters, such as encrypting the data or using alternative methods for storing and transmitting sensitive information. As a temporary workaround, consider disabling the use of sensitive information in URL parameters until a more permanent solution is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-4397

Produtos afetados

Ibm Cloud Orchestrator
Ibm Cloud Orchestrator Enterprise