CVE-2017-1207: Medium severity ibm websphere message broker vulnerability
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1207?
CVE-2017-1207 has a medium severity rating due to the exposure of user credentials in plain text.
How do I fix CVE-2017-1207?
To fix CVE-2017-1207, secure user credentials by storing them in an encrypted format and apply any available patches from IBM.
Which versions are affected by CVE-2017-1207?
CVE-2017-1207 affects IBM WebSphere Message Broker versions 8.0.0.0 through 8.0.0.7 and IBM Integration Bus versions 9.0.0 through 10.0.7.
What are the risks associated with CVE-2017-1207?
The risks associated with CVE-2017-1207 include unauthorized access to user credentials by local users, potentially leading to data breaches.
Is there a workaround for CVE-2017-1207?
While the recommended solution is to patch the software, an immediate workaround includes implementing strict access controls to limit local user access.