CVE-2015-1984

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:infosphere_master_data_management:9.1:*:*:*:collaborative:*:*:*
cpe:2.3:a:ibm:infosphere_master_data_management:10.1:*:*:*:collaborative:*:*:*
cpe:2.3:a:ibm:infosphere_master_data_management:11.0:*:*:*:collaborative:*:*:*
cpe:2.3:a:ibm:infosphere_master_data_management:11.3:*:*:*:collaborative:*:*:*
cpe:2.3:a:ibm:infosphere_master_data_management:11.4:*:*:*:collaborative:*:*:*

History

No history.

Information

Published : 2015-07-20 01:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-1984

Mitre link : CVE-2015-1984

CVE.ORG link : CVE-2015-1984


JSON object : View

Products Affected

ibm

  • infosphere_master_data_management
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-264

Permissions, Privileges, and Access Controls