Information Disclosure in IBM MobileFirst Platform Foundation
CVE-2020-4226

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
27 May 2020

What is CVE-2020-4226?

IBM MobileFirst Platform Foundation 8.0.0.0 is susceptible to information disclosure due to the storage of sensitive data in URL parameters. This vulnerability could allow unauthorized parties to gain access to private information if they can access the URLs through server logs, referrer headers, or browser history, thereby posing a serious risk to data confidentiality.

Affected Version(s)

MobileFirst Platform Foundation 8.0.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.