IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21972480 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT12573 | vendor advisory |
http://www.securityfocus.com/bid/79681 | vdb entry |