VulnerabilityModified
CVE-2017-1694
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques.
HIGH 8.1EPSS 0.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- ibm/integration bus
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22011695Vendor Advisory
- http://www.securityfocus.com/bid/102215Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/134165VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22011695Vendor Advisory
- http://www.securityfocus.com/bid/102215Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/134165VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.