IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer log file.
| Software | From | Fixed in |
|---|---|---|
| ibm / filenet_content_manager | 4.5.0 | 4.5.0.x |
| ibm / filenet_content_manager | 4.5.1 | 4.5.1.x |