VulnerabilityModified
CVE-2017-1422
IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information.
LOW 3.3EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.
- CVSS 3.0
- 3.3 LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/maas360 dtm
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22006985Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100415Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127412VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22006985Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100415Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127412VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.