Vulnerability identifier: #VU65728
Vulnerability risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-664
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
IBM Security Guardium Insights
Server applications /
Other server solutions
Vendor: IBM Corporation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to IBM Security Guardium Insights stores sensitive information in URL parameters. A remote unauthenticated attacker with access to the URLs via server logs, referrer header or browser history can use this vulnerability to decrypt highly sensitive information.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
IBM Security Guardium Insights: 2.0.1
External links
https://exchange.xforce.ibmcloud.com/vulnerabilities/174408
https://www.ibm.com/support/pages/node/6323297
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.