CVE Vulnerabilities

CVE-2017-1198

Insertion of Sensitive Information into Log File

Published: Feb 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Bigfix_compliance Ibm 1.7 (including) 1.9.91 (including)

Potential Mitigations

References