Impact
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 allow a remote attacker to obtain sensitive information by capturing session tokens that are improperly included in URLs. The flaw is a CWE‑598 session identifier mishandling, which exposes authentication data or other confidential information. The impact is confined to information disclosure, but it can enable further attacks once valid session tokens are known.
Affected Systems
The vulnerability affects IBM Engineering AI Hub releases 1.0.0, 1.1.0, and 1.2.0. Fixed versions are available in IBM Engineering AI Hub v1.0.01.3.0, v1.1.01.3.0, and v1.2.01.3.0 respectively.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity for information disclosure, a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via crafted URLs that embed session tokens, possibly delivered through phishing or other social engineering techniques. No special conditions are required other than the ability to observe or request URLs containing the tokens.
OpenCVE Enrichment