IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg2C1000229 | patch vendor advisory |
http://www.securityfocus.com/bid/95290 | vdb entry technical description |