The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg1PM41190 | vendor advisory |
http://secunia.com/advisories/46487 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1026278 | vdb entry |