Vulnerability Bulletins |
IBM Security Bulletin: A User Can Access Information With a Higher Sensitivity Level Than They Have Access To (CVE-2015-7401) |
|
| Affected software | IBM |
|
An already authenticated user can access information with a higher sensitivity level than they have access to. This can be achieved by manipulating a URL to alter a specific parameter resulting in a privilege escalation to view files they should not be able to. CVE(s): CVE-2015-7401Affected product(s) and affected version(s):IBM Curam Social Program Management 6.1.0.0 - 6.1.0.1 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_a_user_can_access_information_with_a_higher_sensitivity_level_than_they_have_access_to_cve_2015_7401?lang=en_us |
|






