CVE-2017-1731
published 2018-01-30CVE-2017-1731: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated…
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.84%
85.1th percentile
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3080 CVE-2017-3100 flash-plugin: information disclosure issues fixed in APSB17-21
bugzilla·2017-07-11·CVSS 6.5
CVE-2017-3080 [MEDIUM] CVE-2017-3080 CVE-2017-3100 flash-plugin: information disclosure issues fixed in APSB17-21
CVE-2017-3080 CVE-2017-3100 flash-plugin: information disclosure issues fixed in APSB17-21
Adobe Security Bulletin APSB17-21 for Adobe Flash Player describes multiple flaws that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-21:
* Security Bypass which can lead to Information Disclosure - CVE-2017-3080
* Memory Corruption which can lead to Memory address disclosure - CVE-2017-3100
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-21.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:1731 https://access.redhat.com/errata/RHSA-2017:1731
Bugzilla
CVE-2017-3099 flash-plugin: code execution issue fixed in APSB17-21
bugzilla·2017-07-11·CVSS 8.8
CVE-2017-3099 [HIGH] CVE-2017-3099 flash-plugin: code execution issue fixed in APSB17-21
CVE-2017-3099 flash-plugin: code execution issue fixed in APSB17-21
Adobe Security Bulletin APSB17-21 for Adobe Flash Player describes a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-21:
* Memory Corruption which can lead to Remote Code Execution - CVE-2017-3099
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-21.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:1731 https://access.redhat.com/errata/RHSA-2017:1731
http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-Rhttp://www.securityfocus.com/bid/102911http://www.securitytracker.com/id/1040356https://exchange.xforce.ibmcloud.com/vulnerabilities/134912http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-Rhttp://www.securityfocus.com/bid/102911http://www.securitytracker.com/id/1040356https://exchange.xforce.ibmcloud.com/vulnerabilities/134912
2018-01-30
Published