Information Disclosure in IBM MobileFirst Platform Foundation
CVE-2020-4226
5.9MEDIUM
Summary
IBM MobileFirst Platform Foundation 8.0.0.0 is susceptible to information disclosure due to the storage of sensitive data in URL parameters. This vulnerability could allow unauthorized parties to gain access to private information if they can access the URLs through server logs, referrer headers, or browser history, thereby posing a serious risk to data confidentiality.
Affected Version(s)
MobileFirst Platform Foundation 8.0.0.0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved