Vulnerability identifier: #VU83999
Vulnerability risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-256
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
IBM API Connect
Client/Desktop applications /
Office applications
Vendor:
Description
The vulnerability allows a local user to gain access to sensitive information.
The
vulnerability exists due to IBM API Connect V10 stores user credentials
in browser cache. A local user can recover the browser cache and gain
unauthorized access to the application.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
External links
http://www.ibm.com/support/pages/node/7087806
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.