IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7112504 | vendor advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/275038 | vdb entry vendor advisory |