IBM Security Verify Access версий с 10.0 по 10.0.9.2 и IBM Verify Identity Access с 11.0 по 11.0.3 и IBM Verify Identity Access Container с 11.0 по 11.0.3 могут позволить удаленному злоумышленнику получить доступ к конфиденциальной информации из-за непоследовательной интерпретации HTTP-запроса обратным прокси-сервером.
Показать оригинальное описание (EN)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 4
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Ibm Security_Verify_Access
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
|
10.0.0
|
<= 10.0.9.2
|
|
Ibm Security_Verify_Access
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix1:*:*:*:*:*:*
|
— | — |
|
Ibm Verify_Identity_Access
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
|
11.0
|
<= 11.0.3
|
|
Ibm Verify_Identity_Access_Container
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*
|
11.0.0.0
|
<= 11.0.3.0
|