VulnerabilityModified
CVE-2018-1757
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application.
MEDIUM 5.3EPSS 1.71%
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- ibm/security identity governance and intelligence
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10728883Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148601Patch, VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10728883Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148601Patch, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.