First published: Wed Jul 12 2017(Updated: )
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Daeja ViewONE | =4.1.5 | |
IBM Daeja ViewONE | =4.1.5 | |
IBM Daeja ViewONE | =4.1.5 | |
IBM Daeja ViewONE | =4.1.5.1 | |
IBM Daeja ViewONE | =4.1.5.1 | |
IBM Daeja ViewONE | =4.1.5.1 | |
IBM Daeja ViewONE | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1308 is considered a high-severity vulnerability due to improper access controls allowing authenticated attackers to download sensitive files.
To resolve CVE-2017-1308, you should apply the latest security patches provided by IBM for the affected versions of Daeja ViewONE.
CVE-2017-1308 affects IBM Daeja ViewONE versions 4.1.5, 4.1.5.1, and 5.0.
CVE-2017-1308 can be exploited by authenticated attackers who have access to the system.
The consequences of CVE-2017-1308 include unauthorized access to sensitive files, leading to possible data breaches.