VulnerabilityModified
CVE-2017-1698
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system.
MEDIUM 5.3EPSS 1.56%
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22011519Vendor Advisory
- http://www.securityfocus.com/bid/102281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040043Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/134390Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg22011519Vendor Advisory
- http://www.securityfocus.com/bid/102281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040043Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/134390Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.