VulnerabilityModified
CVE-2017-1480
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user.
MEDIUM 4.3EPSS 1.75%
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- ibm/security access manager · ibm/security access manager for web · ibm/security access manager for mobile
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22012309Patch, Vendor Advisory
- http://www.securityfocus.com/bid/104471Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/128617VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22012309Patch, Vendor Advisory
- http://www.securityfocus.com/bid/104471Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/128617VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.