Information disclosure in IBM Security Guardium - CVE-2017-1272
Published: December 11, 2018 / Updated: December 18, 2018
IBM Security Guardium
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the application stores sensitive information in URL parameters. A remote attacker can gain access to potentially sensitive information if unauthorized parties have access to the URLs via server logs, referrer header or browser history.