CVE-2017-1240
published 2017-11-27CVE-2017-1240: IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.
PriorityP418medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.92%
56.0th percentile
IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.
Affected
110 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hjg-g7x8-jf42: IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses
ghsa_unreviewed·2022-05-17
CVE-2017-1240 [MEDIUM] CWE-200 GHSA-2hjg-g7x8-jf42: IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses
IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.
GHSA
scalarmult() vulnerable to degenerate public keys
ghsa·2021-08-25
CVE-2017-1000168 [MEDIUM] CWE-1240 scalarmult() vulnerable to degenerate public keys
scalarmult() vulnerable to degenerate public keys
The scalarmult() function included in previous versions of this crate accepted all-zero public keys, for which the resulting Diffie-Hellman shared secret will always be zero regardless of the private key used.
This issue was fixed by checking for this class of keys and rejecting them if they are used.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg22010512http://www.securityfocus.com/bid/101976https://exchange.xforce.ibmcloud.com/vulnerabilities/124359http://www.ibm.com/support/docview.wss?uid=swg22010512http://www.securityfocus.com/bid/101976https://exchange.xforce.ibmcloud.com/vulnerabilities/124359
2017-11-27
Published