IBM Spectrum Protect Plus 10.1.0 up to and including 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an malicious user to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm spectrum_protect_plus |