CVE-2017-1601
published 2018-05-02CVE-2017-1601: IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.50%
82.8th percentile
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
bugzilla·2017-05-11·CVSS 4.1
CVE-2017-7497 [MEDIUM] CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
Gellert Kis of Red Hat reports:
Dialog for creating cloud volumes (cinder provider) does not filter cloud tenants for user. In this way users can create storage volumes in any tenant. Not only in their own tenant. This currently affects CFME 5.7.2 and 5.8.0.
Discussion:
Acknowledgments:
Name: Gellert Kis (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
Bugzilla
CVE-2016-7047 cfme: API leaks any MiqReportResult
bugzilla·2016-09-08·CVSS 4.3
CVE-2016-7047 [MEDIUM] CVE-2016-7047 cfme: API leaks any MiqReportResult
CVE-2016-7047 cfme: API leaks any MiqReportResult
It was found that The API leaks any MiqReportResult to user that has entitlement to this feature.
Discussion:
Acknowledgments:
Name: Simon Lukasik (Red Hat)
---
Scope is bigger than originally anticipated. Has several entry points. Affects UI as well.
Will fix everything in this bug. As it is all related to MiqReportResult leakage.
---
*** Bug 1441502 has been marked as a duplicate of this bug. ***
---
*** This bug has been marked as a duplicate of bug 1435396 ***
---
Marked wrong bug as duplicate.
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601
---
This issue has been addressed in the following products:
Clou
Bugzilla
CVE-2016-4457 CFME: default certificate used across all installs
bugzilla·2016-05-31·CVSS 7.5
CVE-2016-4457 [HIGH] CVE-2016-4457 CFME: default certificate used across all installs
CVE-2016-4457 CFME: default certificate used across all installs
Šimon Lukašík of Red Hat reports:
CloudForms ships a default encryption certificate and key for the web interface.
Discussion:
Acknowledgments:
Name: Simon Lukasik (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1367 https://access.redhat.com/errata/RHSA-2017:1367
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601
http://www.ibm.com/support/docview.wss?uid=swg22014230http://www.securitytracker.com/id/1040899https://exchange.xforce.ibmcloud.com/vulnerabilities/132624http://www.ibm.com/support/docview.wss?uid=swg22014230http://www.securitytracker.com/id/1040899https://exchange.xforce.ibmcloud.com/vulnerabilities/132624
2018-05-02
Published