PT-2021-14055 · Ibm · Ibm Security Secret Server

Published

2021-09-14

·

Updated

2022-07-12

·

CVE-2021-20582

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Security Secret Server versions up to 11.0
Description: The issue arises from the storage of sensitive information in URL parameters, potentially leading to information disclosure if unauthorized parties access the URLs through server logs, referrer headers, or browser history.
Recommendations: For IBM Security Secret Server versions up to 11.0, consider implementing measures to restrict access to server logs and referrer headers, and advise users to clear their browser history regularly to minimize the risk of information disclosure. As a temporary workaround, consider configuring the server to not store sensitive information in URL parameters until a more permanent solution is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20582

Affected Products

Ibm Security Secret Server