VulnerabilityModified
CVE-2017-1107
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system.
MEDIUM 4.3EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/marketing platform
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/108918Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/120906VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10887815Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108918Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/120906VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10887815Broken Link, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.