The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21682627 | |
http://www-01.ibm.com/support/docview.wss?uid=swg24038045 | |
http://secunia.com/advisories/60709 | third party advisory |
http://secunia.com/advisories/61071 | third party advisory |
http://www.securityfocus.com/bid/69643 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/93912 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21681449 | patch vendor advisory |