CVE-2017-1474

EUVD-2017-10490
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ibmCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_access_manager
9.0.0 ≤
𝑥
≤ 9.0.3.1
ibmsecurity_access_manager_for_mobile
8.0.0 ≤
𝑥
≤ 8.0.1.6
ibmsecurity_access_manager_for_web
7.0.0 ≤
𝑥
≤ 7.0.0.32
ibmsecurity_access_manager_for_web
8.0.0 ≤
𝑥
≤ 8.0.1.6
𝑥
= Vulnerable software versions