IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130.
The product uses a cross-domain policy file that includes domains that should not be trusted.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7113759 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/275130 | vdb entry vendor advisory |