Information disclosure in IBM Corporation products - CVE-2023-49877
Published: June 10, 2024
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
IBM Virtualization Engine TS7700 3948-VED
IBM Corporation
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to improper filtering of URLs. A remote user can submit a specially crafted HTTP GET request to view application source code, system configuration information, or other sensitive data related to the Management Interface