SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-1126

IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks.

MEDIUM 5.3EPSS 1.22%

Does this matter?

Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.

Description

IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.22% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
ibm/integration bus · ibm/websphere message broker
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.