#VU28361 Information exposure through externally-generated error message in IBM Security Identity Governance and Intelligence (IGI) - CVE-2020-4248
Published: May 29, 2020
IBM Security Identity Governance and Intelligence (IGI)
IBM Corporation
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application while handling error conditions. A remote user can obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.