CVE-2017-1504
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/129579
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg22006803
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | websphere_application_server | 9.0.0.4 | |
References
- http://www.ibm.com/support/docview.wss?uid=swg22006803
- http://www.securityfocus.com/bid/100137
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129579
- http://www.ibm.com/support/docview.wss?uid=swg22006803
- http://www.securityfocus.com/bid/100137
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129579
Verify integrity in audit chain (admin only). AS-IS.