CVE-2023-50954Use of GET Request Method With Sensitive Query Strings in IBM Infosphere Information Server

Severity
5.3MEDIUMNVD
CNA4.3
EPSS
0.1%
top 64.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30

Description

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-v34f-8v6r-qr8h: IBM InfoSphere Information Server 112024-06-30
CVEList
IBM InfoSphere Information Server information disclosure2024-06-30
CVE-2023-50954 — IBM vulnerability | cvebase