PT-2019-16838 · Ibm · Api Connect
CVE-2019-4008
·
Publicado
2019-02-07
·
Atualizado
2022-12-03
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
API Connect versions 2018.1 through 2018.4.1.1
Description
The issue concerns an access token leak. Authorization tokens in some URLs can result in the tokens being written to log files.
Recommendations
For API Connect versions 2018.1 through 2018.4.1.1, consider restricting access to log files to minimize the risk of exploitation. As a temporary workaround, review and configure logging settings to avoid writing authorization tokens to log files until a patch is available.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Api Connect