Sensitive Information Disclosure in IBM InfoSphere Master Data Management
CVE-2015-1982
Currently unrated
Summary
The vulnerability in IBM InfoSphere Master Data Management Collaborative Edition versions 9.1, 10.1, 11.0, 11.3, and 11.4 prior to FP03 allows remote authenticated users to extract sensitive information. This occurs when an attacker sends a specially crafted request that prompts the system to display the full file path in an error message, potentially revealing sensitive data and system configuration details.
References
Timeline
Vulnerability published
Vulnerability Reserved