IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21660191 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM95817 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/86420 | vdb entry |