CVE-2017-1395: Infoleak
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1395?
The severity of CVE-2017-1395 is classified as moderate, as it allows potential exposure of sensitive information.
How do I fix CVE-2017-1395?
To fix CVE-2017-1395, ensure that HTTP Strict Transport Security is properly enabled in your IBM Security Identity Governance and Intelligence Virtual Appliance.
What versions are affected by CVE-2017-1395?
CVE-2017-1395 affects versions 5.2 to 5.2.3.2 of the IBM Security Identity Governance and Intelligence Virtual Appliance.
Who can exploit CVE-2017-1395?
CVE-2017-1395 can be exploited by a remote attacker who can gain access to the affected system.
What type of information can be exposed by CVE-2017-1395?
CVE-2017-1395 can lead to the exposure of sensitive information due to inadequate security configurations.