CVE-2017-1694Cleartext Transmission of Sensitive Info in IBM Integration BUS

Severity
8.1HIGHNVD
EPSS
0.1%
top 67.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 13

Description

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/integration_bus10.0, 9.0+1
NVDibm/integration_bus20 versions+19

🔴Vulnerability Details

2
GHSA
GHSA-qwgr-49qr-w98v: IBM Integration Bus 92022-05-13
CVEList
CVE-2017-1694: IBM Integration Bus 92017-12-20
CVE-2017-1694 — IBM Integration BUS vulnerability | cvebase