漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Rational Build Forge信息泄露漏洞
Vulnerability Description
IBM Rational Build Forge 是专门用于构建和发布流程管理的软件。 IBM Rational Build Forge 7.1.0从认证服务器重定向到PHP脚本的过程中使用了HTTP GET方法。攻击者更容易通过读取web-server访问日志,web-server Referer日志或浏览器历史记录发现会话ID。
CVSS Information
N/A
Vulnerability Type
N/A