CVE-2017-1362: High severity IBM Security Identity Manager vulnerability
Published Sep 25, 2017
·Updated
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
Affected Software
2 affected components
IBM Security Identity Manager=6.0
IBM Security Identity Manager=7.0
Remediation
Patch Available
Event History
Sep 25, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1362?
The severity of CVE-2017-1362 is considered high due to the exposure of user credentials in plain text.
2
How do I fix CVE-2017-1362?
To fix CVE-2017-1362, upgrade to a version of IBM Security Identity Manager that addresses this vulnerability.
3
Which versions of IBM Security Identity Manager are affected by CVE-2017-1362?
CVE-2017-1362 affects IBM Security Identity Manager versions 6.0 and 7.0.
4
What are the implications of CVE-2017-1362?
The implications of CVE-2017-1362 include unauthorized access to user credentials by local users.
5
Can CVE-2017-1362 be exploited remotely?
CVE-2017-1362 cannot be exploited remotely as it requires local access to the affected system.