IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103477 | vdb entry third party advisory |
http://www.ibm.com/support/docview.wss?uid=swg22014815 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/132625 | vdb entry vendor advisory |