CVE-2017-1309: High severity ibm infosphere master data management collaborative server vulnerability
Published Jul 19, 2017
·Updated
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
Affected Software
5 affected components
IBM InfoSphere Master Data Management Server=11.0
IBM InfoSphere Master Data Management Server=11.3
IBM InfoSphere Master Data Management Server=11.4
IBM InfoSphere Master Data Management Server=11.5
IBM InfoSphere Master Data Management Server=11.6
Remediation
Patch Available
Event History
Jul 19, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1309?
CVE-2017-1309 is categorized as a medium severity vulnerability due to the exposure of user credentials.
2
How do I fix CVE-2017-1309?
To fix CVE-2017-1309, update IBM InfoSphere Master Data Management Server to a version that addresses this credential storage issue.
3
What impact does CVE-2017-1309 have on security?
CVE-2017-1309 can lead to unauthorized access as user credentials are stored in plain text, making them readable by local users.
4
Which versions of IBM InfoSphere Master Data Management Server are affected by CVE-2017-1309?
CVE-2017-1309 affects IBM InfoSphere Master Data Management Server versions 11.0 through 11.6.
5
Is CVE-2017-1309 a local or remote vulnerability?
CVE-2017-1309 is a local vulnerability, as it requires local access to read the stored plain text credentials.