IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://exchange.xforce.ibmcloud.com/vulnerabilities/111786 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21980233 | vendor advisory |