CVE-2017-1379: Infoleak
Published Jun 15, 2017
·Updated
IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.
Affected Software
12 affected components
IBM API Connect=5.0.0.0
IBM API Connect=5.0.0.1
IBM API Connect=5.0.1.0
IBM API Connect=5.0.2.0
IBM API Connect=5.0.3.0
IBM API Connect=5.0.4.0
IBM API Connect=5.0.5.0
IBM API Connect=5.0.6.0
IBM API Connect=5.0.6.1
IBM API Connect=5.0.6.2
IBM API Connect=5.0.7.0
IBM API Connect=5.0.7.1
Remediation
Patch Available
Event History
Jun 15, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1379?
The severity of CVE-2017-1379 is classified as a medium risk due to the potential for sensitive information disclosure.
2
How do I fix CVE-2017-1379?
To fix CVE-2017-1379, it is recommended to apply the latest security updates provided by IBM for IBM API Connect.
3
What products are affected by CVE-2017-1379?
CVE-2017-1379 affects multiple versions of IBM API Connect including 5.0.0.0 to 5.0.7.1.
4
What type of attack is possible with CVE-2017-1379?
CVE-2017-1379 allows a remote attacker to obtain sensitive information via improper request handling.
5
Is there a workaround for CVE-2017-1379?
Currently, the best approach for CVE-2017-1379 is to implement the recommended security patches rather than relying on workarounds.