Vulnerability Name: | CVE-2017-1669 (CCN-133636) | ||||||||||||
Assigned: | 2016-11-30 | ||||||||||||
Published: | 2018-01-03 | ||||||||||||
Updated: | 2018-01-12 | ||||||||||||
Summary: | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636. | ||||||||||||
CVSS v3 Severity: | 3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1669 Source: CCN Type: IBM Security Bulletin 1997955 (Security Key Lifecycle Manager) IBM Security Key Lifecycle Manager is affected by exposure of sensitive information stored in URL parameters (CVE-2017-1669) Source: CONFIRM Type: Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg21997955 Source: BID Type: Third Party Advisory, VDB Entry 102468 Source: CCN Type: BID-102468 IBM Security Key Lifecycle Manager CVE-2017-1669 Information Disclosure Vulnerability Source: MISC Type: VDB Entry, Vendor Advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/133636 Source: XF Type: UNKNOWN ibm-tivoli-cve20171669-info-disc(133636) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |