IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/48967 | third party advisory |
http://www.ibm.com/support/docview.wss?uid=swg21592188 | |
http://secunia.com/advisories/48968 | third party advisory |
http://www.securityfocus.com/bid/53247 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74371 | vdb entry |