IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21655578 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/88193 | vdb entry |