CVE-2017-1423

Severity
5.3MEDIUM
EPSS
0.2%
top 55.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 14

Description

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/websphere_portal8.5, 9.0+1
NVDibm/websphere_portal8.5.0.0, 9.0.0.0+1

🔴Vulnerability Details

2
GHSA
GHSA-h63f-6vhg-f94h: IBM WebSphere Portal 82022-05-14
CVEList
CVE-2017-1423: IBM WebSphere Portal 82017-12-20
CVE-2017-1423 (MEDIUM CVSS 5.3) | IBM WebSphere Portal 8.5 and 9.0 ex | cvebase.io