CVE-2017-1501Sensitive Information Exposure in IBM Websphere Application Server

Severity
5.9MEDIUMNVD
EPSS
0.7%
top 27.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateMay 17

Description

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/websphere_application_server8.0, 8.5, 9.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5p86-qj67-4q39: IBM WebSphere Application Server 82022-05-17
CVEList
CVE-2017-1501: IBM WebSphere Application Server 82017-08-18
CVE-2017-1501 — Sensitive Information Exposure in IBM | cvebase