VulnerabilityModified
CVE-2017-1257
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users.
MEDIUM 4.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/security guardium
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22010431Vendor Advisory
- http://www.securityfocus.com/bid/102308Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/124684Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg22010431Vendor Advisory
- http://www.securityfocus.com/bid/102308Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/124684Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.