CVE-2017-1474

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ibmCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
ibmsecurity_access_manager
9.0.0 ≤
𝑥
≤ 9.0.3.1
ibmsecurity_access_manager_for_mobile
8.0.0 ≤
𝑥
≤ 8.0.1.6
ibmsecurity_access_manager_for_web
7.0.0 ≤
𝑥
≤ 7.0.0.32
ibmsecurity_access_manager_for_web
8.0.0 ≤
𝑥
≤ 8.0.1.6
𝑥
= Vulnerable software versions