IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21991154 | patch vendor advisory |
http://www.securityfocus.com/bid/94848 | vdb entry third party advisory |