First published: Mon Aug 06 2018(Updated: )
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | =5.2 | |
IBM Security Identity Governance and Intelligence | =5.2.1 | |
IBM Security Identity Governance and Intelligence | =5.2.2 | |
IBM Security Identity Governance and Intelligence | =5.2.2.1 | |
IBM Security Identity Governance and Intelligence | =5.2.3 | |
IBM Security Identity Governance and Intelligence | =5.2.3.1 | |
IBM Security Identity Governance and Intelligence | =5.2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1366 has a medium severity level due to its potential for allowing decryption of sensitive information.
To mitigate CVE-2017-1366, upgrade to a version of IBM Security Identity Governance that uses stronger cryptographic algorithms.
CVE-2017-1366 affects IBM Security Identity Governance Virtual Appliance versions 5.2 to 5.2.3.2.
Organizations face the risk of exposing highly sensitive information due to the use of weaker than expected cryptographic algorithms.
There currently are no specific workarounds for CVE-2017-1366; the recommended action is to upgrade to a secure version.