CVE-2017-1284: Infoleak
Published Jul 10, 2017
·Updated
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.
Affected Software
2 affected components
IBM WebSphere MQ=9.0.1
IBM WebSphere MQ=9.0.2
Event History
Jul 10, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1284?
CVE-2017-1284 is considered a high severity vulnerability as it allows local users to access sensitive information such as user credentials.
2
How do I fix CVE-2017-1284?
To fix CVE-2017-1284, upgrade to IBM WebSphere MQ version 9.0.3 or later.
3
Who is affected by CVE-2017-1284?
CVE-2017-1284 affects local users of IBM WebSphere MQ versions 9.0.1 and 9.0.2.
4
What type of vulnerability is CVE-2017-1284?
CVE-2017-1284 is classified as an information disclosure vulnerability.
5
Can CVE-2017-1284 be exploited remotely?
No, CVE-2017-1284 cannot be exploited remotely; it requires local access to the system.