CVE-2017-1758
published 2018-02-21CVE-2017-1758: IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4…
PriorityP341high7.1CVSS 3.0
AVNACLPRLUINSUCHINAL
EPSS
1.64%
73.7th percentile
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| exiv2 | exiv2 | >= 0 < 0.23-1ubuntu2.2 | 0.23-1ubuntu2.2 |
| exiv2 | exiv2 | >= 0 < 0.25-2.1ubuntu16.04.3 | 0.25-2.1ubuntu16.04.3 |
| exiv2 | exiv2 | >= 0 < 0.25-3.1ubuntu0.18.04.2 | 0.25-3.1ubuntu0.18.04.2 |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | control_center | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | financial_transaction_manager | — | — |
| ibm | transformation_extender_advanced | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qpc-h4mf-gvrr: IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6
ghsa_unreviewed·2022-05-14
CVE-2017-1758 [HIGH] CWE-611 GHSA-2qpc-h4mf-gvrr: IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
OSV
exiv2 vulnerabilities
osv·2019-01-10·CVSS 7.5
CVE-2017-9239 exiv2 vulnerabilities
exiv2 vulnerabilities
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
CVE-2017-9239 only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2017-11591, CVE-2017-11683, CVE-2017-14859, CVE-2017-14862,
CVE-2017-14864, CVE-2017-17669, CVE-2017-9239, CVE-2018-16336,
CVE-2018-1758)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7530 cfme: Execution of arbitrary methods through filter param
bugzilla·2017-06-27·CVSS 8.8
CVE-2017-7530 [HIGH] CVE-2017-7530 cfme: Execution of arbitrary methods through filter param
CVE-2017-7530 cfme: Execution of arbitrary methods through filter param
It was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users.
Discussion:
Acknowledgments:
Name: Tim Wade (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
Bugzilla
CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
bugzilla·2017-05-11·CVSS 4.1
CVE-2017-7497 [MEDIUM] CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497
Gellert Kis of Red Hat reports:
Dialog for creating cloud volumes (cinder provider) does not filter cloud tenants for user. In this way users can create storage volumes in any tenant. Not only in their own tenant. This currently affects CFME 5.7.2 and 5.8.0.
Discussion:
Acknowledgments:
Name: Gellert Kis (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
Bugzilla
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
bugzilla·2017-03-23·CVSS 6.5
CVE-2017-2664 [MEDIUM] CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
Libor Pichler and Martin Povolny report:
Cloudforms lacks RBAC controls on a variety of methods potentially allowing authenticated users to escalate privileges and use methods they should not have access to.
Discussion:
Acknowledgments:
Name: Libor Pichler (Red Hat), Martin Povolny (Red Hat)
---
*** Bug 1434771 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:3484 https://access.redhat.com/errata/RHSA-2017:3484
Bugzilla
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
bugzilla·2017-02-06·CVSS 5.5
CVE-2017-5595 [MEDIUM] CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
File disclosure and inclusion vulnerability exists in ZoneMinder due to unfiltered user-input being passed to readfile() in views/file.php which allows an authenticated attacker to read local system files (e.g. /etc/passwd) in the context of the web server user (www-data).
References:
http://seclists.org/bugtraq/2017/Feb/6
Upstream patch:
https://github.com/ZoneMinder/ZoneMinder/commit/8b19fca9927cdec07cc9dd09bdcf2496a5ae69b3
Discussion:
Created zoneminder tracking bugs for this issue:
Affects: fedora-all [bug 1419509]
---
Strange, the link above does not contain all three commits which make up this fix.
Please use this link instead:
https://patch-diff.githubusercontent.com/raw/ZoneMinder/ZoneMinder/pull/1758
http://www.ibm.com/support/docview.wss?uid=swg22012828http://www.ibm.com/support/docview.wss?uid=swg22013375http://www.ibm.com/support/docview.wss?uid=swg22013432http://www.securityfocus.com/bid/103130https://exchange.xforce.ibmcloud.com/vulnerabilities/135859http://www.ibm.com/support/docview.wss?uid=swg22012828http://www.ibm.com/support/docview.wss?uid=swg22013375http://www.ibm.com/support/docview.wss?uid=swg22013432http://www.securityfocus.com/bid/103130https://exchange.xforce.ibmcloud.com/vulnerabilities/135859
2018-02-21
Published