Vulnerability Name: | CVE-2017-1355 (CCN-126682) | ||||||||||||
Assigned: | 2016-11-30 | ||||||||||||
Published: | 2017-07-14 | ||||||||||||
Updated: | 2017-12-19 | ||||||||||||
Summary: | IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682. | ||||||||||||
CVSS v3 Severity: | 3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1355 Source: BID Type: Third Party Advisory, VDB Entry 102016 Source: CCN Type: BID-102016 IBM Atlas eDiscovery Process Management CVE-2017-1355 Information Disclosure Vulnerability Source: MISC Type: Issue Tracking, VDB Entry, Vendor Advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/126682 Source: XF Type: UNKNOWN ibm-atlas-cve20171355-info-disc(126682) Source: CCN Type: IBM Security Bulletin 2005836 (Atlas eDiscovery Process Management) IBM Atlas eDiscovery Process Management affected by vulnerability due to sensitive information stored in URL parameters. Source: CONFIRM Type: Issue Tracking, Vendor Advisory https://www.ibm.com/support/docview.wss?uid=swg22005836 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |