There is a vulnerability in Ruby On Rails that is used by IBM License Metric Tool.
CVEID:CVE-2019-16782
**DESCRIPTION:**Rack could allow a remote attacker to obtain sensitive information, caused by using the same session id for querying the backing session storage engine. By using timing attacks, an attacker could exploit this vulnerability to obtain session id information, and use this information to launch further attacks against the affected system.
CVSS Base score: 9.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/173273 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM License Metric Tool | All |
Upgrade to version 9.2.19 or later using the following procedure:
None