IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7174572 | vendor advisory |