Vulnerability Name: | CVE-2017-1597 (CCN-132610) | ||||||||||||
Assigned: | 2016-11-30 | ||||||||||||
Published: | 2018-12-13 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-521 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1597 Source: BID Type: Third Party Advisory, VDB Entry 106236 Source: XF Type: UNKNOWN ibm-guardium-cve20171597-info-disc(132610) Source: XF Type: VDB Entry, Vendor Advisory ibm-guardium-cve20171597-info-disc(132610) Source: CCN Type: IBM Security Bulletin 2014231 (Security Guardium) IBM Security Guardium Database Activity Monitor is affected by a Weak Passsword Policy vulnerability Source: CONFIRM Type: Vendor Advisory https://www.ibm.com/support/docview.wss?uid=swg22014231 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |