PT-2014-6297 · Innovative Interfaces · Innovative Interfaces Encore Discovery Solution

Published

2014-08-29

·

Updated

2018-10-09

·

CVE-2014-5128

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Innovative Interfaces Encore Discovery Solution version 4.3
Description The issue allows remote attackers to potentially obtain sensitive information via unspecified vectors, as the session token is placed in the URI.
Recommendations For Innovative Interfaces Encore Discovery Solution version 4.3, consider removing the session token from the URI as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5128

Affected Products

Innovative Interfaces Encore Discovery Solution