Hi,
Security vulnerability - Full path disclosure on MyFileGateway.
The endpoint /myfilegateway/isomorphic/IDACall is exposed on the Internet on URL https://qua-hipmft-emea.loreal.net:6443
By sending a crafted request with an invalid dataSource parameter, the application leaks a valid filepath on the server.
Response
HTTP/1.1 200 OK
Date: Mon, 14 Dec 2020 10:26:40 GMT
X-FRAME-OPTIONS: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
Cache-Control: no-cache, no-store, private, must-revalidate, max-age=0
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: text/plain;charset=utf-8
Server: HTTP Server
Set-Cookie: JSESSIONID=zp9detwq58xm1hwkzkq76nzbp;Path=/myfilegateway;Secure;HttpOnly
Content-Length: 337
//isc_RPCResponseStart-->[ {affectedRows:0,data:"Can't find dataSource: test_path - please make sure that you have a test_path.ds.xml file for it in one of these locations: [/data/master/IBM/si/install/tmp/local_node1_63021_1423482803/webapp/shared/] ds",invalidateCache:false,isDSResponse:true,queueStatus:-1,status:-1}
]//isc_RPCResponseEnd
Issue 2:
Security vulnerability - Exceptions information leak in MyFileGateway.
Exceptions information leak in MyFileGateway.
The endpoint /myfilegateway/isomorphic/IDACall is exposed on the internet on URLhttps://qua-hipmft-emea.loreal.net:6443.
By sending a crafted request, an uncaught exception in the web application which will return an execution stack trace to the remote user.
We see following NPE coming from smartclient library.
They need to fix this NPE.
		
							
						
					Security vulnerability - Full path disclosure on MyFileGateway.
The endpoint /myfilegateway/isomorphic/IDACall is exposed on the Internet on URL https://qua-hipmft-emea.loreal.net:6443
By sending a crafted request with an invalid dataSource parameter, the application leaks a valid filepath on the server.
Response
HTTP/1.1 200 OK
Date: Mon, 14 Dec 2020 10:26:40 GMT
X-FRAME-OPTIONS: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
Cache-Control: no-cache, no-store, private, must-revalidate, max-age=0
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: text/plain;charset=utf-8
Server: HTTP Server
Set-Cookie: JSESSIONID=zp9detwq58xm1hwkzkq76nzbp;Path=/myfilegateway;Secure;HttpOnly
Content-Length: 337
//isc_RPCResponseStart-->[ {affectedRows:0,data:"Can't find dataSource: test_path - please make sure that you have a test_path.ds.xml file for it in one of these locations: [/data/master/IBM/si/install/tmp/local_node1_63021_1423482803/webapp/shared/] ds",invalidateCache:false,isDSResponse:true,queueStatus:-1,status:-1}
]//isc_RPCResponseEnd
Issue 2:
Security vulnerability - Exceptions information leak in MyFileGateway.
Exceptions information leak in MyFileGateway.
The endpoint /myfilegateway/isomorphic/IDACall is exposed on the internet on URLhttps://qua-hipmft-emea.loreal.net:6443.
By sending a crafted request, an uncaught exception in the web application which will return an execution stack trace to the remote user.
We see following NPE coming from smartclient library.
They need to fix this NPE.

Comment