IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Engineering_ai_hub | Ibm | 1.0.0 (including) | 1.3.0 (excluding) |