IBM Security Bulletin: Exposed Authentication Token in IBM UrbanCode Deploy (CVE-2015-4964)
In previous versions of IBM UrbanCode Deploy, the authentication token is displayed in the execution logs. In certain steps that are run using the admin user permissions, this can allow non-administrator users to impersonate the admin user. In other processes,...
from IBM Product Security Incident Response Team http://ift.tt/1OZESSg
from IBM Product Security Incident Response Team http://ift.tt/1OZESSg