IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM X-Force ID: 269929.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7116830 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/269929 | vdb entry |