CVE-2026-15322
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Engineering AI Hub | 1.0.0 | affected |
| IBM | Engineering AI Hub | 1.1.0 | affected |
| IBM | Engineering AI Hub | 1.2.0 | affected |
Weaknesses
- CWE-598: CWE-598 Use of HTTP Request With Sensitive Query String
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.