CVE-2017-1367
published 2018-07-13CVE-2017-1367: IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to…
PriorityP424medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.21%
64.9th percentile
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | — | — |
| ibm | security_identity_governance_and_intelligence | 5.2.0 – 5.2.3.2 | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2017-2639 CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
bugzilla·2017-03-06·CVSS 6.5
CVE-2017-2639 [MEDIUM] CVE-2017-2639 CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
CVE-2017-2639 CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
Cloudforms fails to properly validate SSL/TLS certificates when communicating with RHEV and OpenShift and using a custom CA.
Discussion:
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1367 https://access.redhat.com/errata/RHSA-2017:1367
Bugzilla
CVE-2016-4457 CFME: default certificate used across all installs
bugzilla·2016-05-31·CVSS 7.5
CVE-2016-4457 [HIGH] CVE-2016-4457 CFME: default certificate used across all installs
CVE-2016-4457 CFME: default certificate used across all installs
Šimon Lukašík of Red Hat reports:
CloudForms ships a default encryption certificate and key for the web interface.
Discussion:
Acknowledgments:
Name: Simon Lukasik (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1367 https://access.redhat.com/errata/RHSA-2017:1367
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601
2018-07-13
Published