CVE-2017-1366Inadequate Encryption Strength in IBM Security Identity Governance AND Intelligence

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.1%
top 74.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 13

Description

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2492-95q9-ghpv: IBM Security Identity Governance Virtual Appliance 52022-05-13
CVEList
CVE-2017-1366: IBM Security Identity Governance Virtual Appliance 52018-08-06

💥Exploits & PoCs

1
Exploit-DB
Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Return the return Instruction2017-11-27
CVE-2017-1366 — Inadequate Encryption Strength in IBM | cvebase