VulnerabilityModified
CVE-2017-1501
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings.
MEDIUM 5.9EPSS 2.03%
Does this matter?
Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22006810Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100394Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039199Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129576VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22006810Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100394Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039199Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129576VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.