CVE-2014-0946

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
9 May 2014

Summary

The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.