CVE-2017-1367: Infoleak
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1367?
CVE-2017-1367 is rated as a high severity vulnerability due to potential sensitive information disclosure.
How do I fix CVE-2017-1367?
To resolve CVE-2017-1367, you should upgrade to a version of IBM Security Identity Governance and Intelligence later than 5.2.3.2.
What types of information are disclosed in CVE-2017-1367?
CVE-2017-1367 can lead to the disclosure of sensitive information included in URL parameters.
Who is affected by CVE-2017-1367?
CVE-2017-1367 affects users running IBM Security Identity Governance and Intelligence Virtual Appliance versions 5.2 through 5.2.3.2.
What can attackers access in relation to CVE-2017-1367?
Attackers may gain access to sensitive information if they can view server logs, referrer headers, or browser history containing the vulnerable URLs.