CVE-2017-1474

Severity
5.3MEDIUM
EPSS
0.2%
top 59.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateMay 13

Description

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/security_access_manager9.0.09.0.3.1+2
CVEListV5ibm/security_access_manager20 versions+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9g4r-jrww-j742: IBM Security Access Manager Appliance 72022-05-13
CVEList
CVE-2017-1474: IBM Security Access Manager Appliance 72018-06-06

💬Community

1
Bugzilla
CVE-2017-11730 ming: heap-based buffer over-read in OpCode via decompileINCR_DECR2017-07-31
CVE-2017-1474 (MEDIUM CVSS 5.3) | IBM Security Access Manager Applian | cvebase.io