IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651.
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7148438 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/287651 | vdb entry |