CVE-2017-1211
low
CVSS v3
2.5
CVSS v2
1.9
VIR risk
2.5
Description
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.
Predictions
Exploit likelihood
27%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/123851
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg22008011
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | daeja_viewone | 4.1.5 | |
| ibm | daeja_viewone | 4.1.5.1 | |
| ibm | daeja_viewone | 5.0.0 | |
| ibm | daeja_viewone | 5.0.2 | |
References
- http://www.ibm.com/support/docview.wss?uid=swg22008011
- http://www.securityfocus.com/bid/101526
- https://exchange.xforce.ibmcloud.com/vulnerabilities/123851
- http://www.ibm.com/support/docview.wss?uid=swg22008011
- http://www.securityfocus.com/bid/101526
- https://exchange.xforce.ibmcloud.com/vulnerabilities/123851
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.