CVE-2017-1154

Severity
6.5MEDIUM
EPSS
0.3%
top 51.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 17

Description

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/algo_one4.9.1, 5.0.0, 5.1.0+2
CVEListV5ibm_corporation/algo_one9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2cg5-vvw2-c4ff: IBM Algorithmics One-Algo Risk Application 42022-05-17
CVEList
CVE-2017-1154: IBM Algorithmics One-Algo Risk Application 42017-03-31

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - 'IOCTL_VOLUME_GET_VOLUME_DISK_EXTENTS' volmgr Pool Memory Disclosure2017-06-21