VulnerabilityModified
CVE-2017-1423
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component.
MEDIUM 5.3EPSS 1.29%
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://www.securitytracker.com/id/1040017Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127476VDB Entry
- https://www.ibm.com/support/docview.wss?uid=swg22011400Vendor Advisory
- http://www.securitytracker.com/id/1040017Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127476VDB Entry
- https://www.ibm.com/support/docview.wss?uid=swg22011400Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.