IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7158425 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/288182 | vdb entry vendor advisory |