IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/97713 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21690185 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI23430 | vendor advisory |