CVE Vulnerabilities

CVE-2023-50328

Use of GET Request Method With Sensitive Query Strings

Published: Feb 02, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

Name Vendor Start Version End Version
Powersc Ibm 1.3 (including) 1.3 (including)
Powersc Ibm 2.0 (including) 2.0 (including)
Powersc Ibm 2.1 (including) 2.1 (including)

Potential Mitigations

References