4 ms·
The way IBM handles this is pretty bad. No company, especially the ones selling a security product, should ignore security researchers reports and feedbacks Al
by reader_1000 6y ago
The way IBM handles this is pretty bad. No company, especially the ones selling a security product, should ignore security researchers reports and feedbacks
Also the bugs described in article are quite surprising since for a IBM-sized company, you expect them to have solid authentication/authorization framework which they use for all their products.
Is this a acquired product? Authentication mechanism is very unusual. Why would anyone save a session id coming from the user? This is more than trusting user input, I think.
Also ../../etc/passwd attack is a kind of vulnerability that almost every automated vulnerabilty scanner scans.
Most people assume that authenticated pages do not need that much security precautions however as articles shows, when combined with authentication bypass vulnerabilities, you basically give keys of your systems to the attacker.
- osipov 6y ago>you expect them to have solid authentication/authorization framework which they use for all their products haha