Server path disclosure pattern is present in IBM Dynamic Workload Console 9.5
CVEID:CVE-2020-4674
**DESCRIPTION:**IBM Workload Automation stores sensitive information in URLs that could aid in further attacks against the system.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/186287 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Workload Automation | 9.5.x |
APAR IJ30009 has been opened to address CVE-2020-4674.
Apar IJ30009 has been included in IBM Workload Scheduler 9.5 FP03 and it is already available on FixCentral.
None