IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7180313 | vendor advisory |