PT-2024-4817 · Ibm · Ibm Infosphere Information Server
Rüveyda Durul Çiftci
·
Published
2024-06-30
·
Updated
2024-07-31
·
CVE-2024-31898
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM InfoSphere Information Server version 11.7
Description:
The issue is related to an error in handling user-controlled authorization keys, which could allow a remote attacker to disclose protected information or modify arbitrary data. It is also described as allowing an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
Recommendations:
For IBM InfoSphere Information Server version 11.7, consider restricting access to sensitive information and implementing additional authentication measures to prevent bypassing authentication using insecure direct object references. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Infosphere Information Server