Last Modified: Jun 28, 2022
Affected Product:
See more info
BIG-IQ Platform
Opened: Feb 04, 2022
Severity: 3-Major
Using the wrong syntax in the login request payload reflects the whole request payload in the response, which may contain the original password from the request in clear text.
Request Password is shown in cleartext
Using "loginReference" instead of "loginProviderName" in the login request
None
None