IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: 275109.
The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Powersc | Ibm | 1.3 (including) | 1.3 (including) |
| Powersc | Ibm | 2.0 (including) | 2.0 (including) |
| Powersc | Ibm | 2.1 (including) | 2.1 (including) |