CVE-2017-1353
low
CVSS v3
3.5
CVSS v2
3.5
VIR risk
3.5
Description
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.
Predictions
Exploit likelihood
45%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://www.ibm.com/support/docview.wss?uid=swg22005827
Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/126680
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.3 | |
| ibm | atlas_ediscovery_process_management | 6.0.3.2 | |
| ibm | atlas_ediscovery_process_management | 6.0.3.3 | |
| ibm | atlas_ediscovery_process_management | 6.0.3.4 | |
| ibm | atlas_ediscovery_process_management | 6.0.3.5 | |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.