CVE-2017-1366: Weak Encryption
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1366?
CVE-2017-1366 has a medium severity level due to its potential for allowing decryption of sensitive information.
How do I fix CVE-2017-1366?
To mitigate CVE-2017-1366, upgrade to a version of IBM Security Identity Governance that uses stronger cryptographic algorithms.
Which versions of IBM Security Identity Governance are affected by CVE-2017-1366?
CVE-2017-1366 affects IBM Security Identity Governance Virtual Appliance versions 5.2 to 5.2.3.2.
What risk does CVE-2017-1366 pose to organizations?
Organizations face the risk of exposing highly sensitive information due to the use of weaker than expected cryptographic algorithms.
Is there a workaround for CVE-2017-1366?
There currently are no specific workarounds for CVE-2017-1366; the recommended action is to upgrade to a secure version.