IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Powersc | Ibm | 1.3 (including) | 1.3 (including) |
Powersc | Ibm | 2.0 (including) | 2.0 (including) |
Powersc | Ibm | 2.1 (including) | 2.1 (including) |