IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg22015569 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/121154 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/104011 | third party advisory vdb entry |