PT-2020-10970 · Ibm · Ibm Security Directory Server

Published

2020-02-04

·

Updated

2020-02-04

·

CVE-2019-4562

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Directory Server version 6.4.0
Description The issue concerns the storage of sensitive information in URLs, which may lead to information disclosure if unauthorized parties gain access to these URLs through server logs, referer headers, or browser history.
Recommendations For IBM Security Directory Server version 6.4.0, consider restricting access to server logs and implementing measures to protect browser history to minimize the risk of information disclosure. As a temporary workaround, avoid using sensitive information in URLs until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4562

Affected Products

Ibm Security Directory Server