IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6597511 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/199169 | vdb entry vendor advisory |