IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/128606 | VDB Entry Vendor Advisory |
http://www.ibm.com/support/docview.wss?uid=swg22012329 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/104476 | VDB Entry Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2018-06-06 10:29
Updated : 2019-10-09 16:26
NVD link : CVE-2017-1474
Mitre link : CVE-2017-1474
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
ibm
- security_access_manager_for_mobile
- security_access_manager
- security_access_manager_for_web