Information Disclosure in IBM MobileFirst Platform Foundation
CVE-2020-4226

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 May 2020

Summary

IBM MobileFirst Platform Foundation 8.0.0.0 is susceptible to information disclosure due to the storage of sensitive data in URL parameters. This vulnerability could allow unauthorized parties to gain access to private information if they can access the URLs through server logs, referrer headers, or browser history, thereby posing a serious risk to data confidentiality.

Affected Version(s)

MobileFirst Platform Foundation 8.0.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.