CVE-2017-1286Sensitive Information Exposure in IBM Urbancode Deploy

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 57.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 13
Latest updateMay 14

Description

Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cpw6-3m7w-xvrc: Sensitive information about the configuration of the IBM UrbanCode Deploy 62022-05-14
CVEList
CVE-2017-1286: Sensitive information about the configuration of the IBM UrbanCode Deploy 62018-08-13

💬Community

1
Bugzilla
CVE-2017-14868 restlet: XML external entity injection2017-10-05
CVE-2017-1286 — Sensitive Information Exposure in IBM | cvebase