IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wizard) access restrictions by visiting context roots in HTTP sessions on port 8080.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21620359 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78379 | vdb entry |