Sensitive Information Disclosure in IBM InfoSphere Master Data Management
CVE-2015-1982

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 July 2015

Summary

The vulnerability in IBM InfoSphere Master Data Management Collaborative Edition versions 9.1, 10.1, 11.0, 11.3, and 11.4 prior to FP03 allows remote authenticated users to extract sensitive information. This occurs when an attacker sends a specially crafted request that prompts the system to display the full file path in an error message, potentially revealing sensitive data and system configuration details.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.