PT-2021-14055 · Ibm · Ibm Security Secret Server
Published
2021-09-14
·
Updated
2022-07-12
·
CVE-2021-20582
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Secret Server versions up to 11.0
Description:
The issue arises from the storage of sensitive information in URL parameters, potentially leading to information disclosure if unauthorized parties access the URLs through server logs, referrer headers, or browser history.
Recommendations:
For IBM Security Secret Server versions up to 11.0, consider implementing measures to restrict access to server logs and referrer headers, and advise users to clear their browser history regularly to minimize the risk of information disclosure. As a temporary workaround, consider configuring the server to not store sensitive information in URL parameters until a more permanent solution is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Secret Server