IBM Security Bulletin: IBM Cloud Automation Manager is affected by a forbidden resouce redirect for bad API path CVE-2019-4132

IBM Cloud Automation Manager will redirect when a bad API path is requested rather than issuing a 404. User may expect an error but be redirected to a home page instead.

CVE(s): CVE-2019-4132

Affected product(s) and affected version(s):
IBM Cloud Automation Manager 3.1.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10967477
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158274

The post IBM Security Bulletin: IBM Cloud Automation Manager is affected by a forbidden resouce redirect for bad API path CVE-2019-4132 appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2HnH3nv