VulnerabilityModified
CVE-2017-1126
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks.
MEDIUM 5.3EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/integration bus · ibm/websphere message broker
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22008470Issue Tracking, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101104Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121341VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22008470Issue Tracking, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101104Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121341VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.