CVE-2011-1839

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
28/04/2011
Last modified:
11/04/2025

Description

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:rational_build_forge:7.1.0:*:*:*:*:*:*:*