First published: Fri Jul 13 2018(Updated: )
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | >=5.2<=5.2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1395 is classified as moderate, as it allows potential exposure of sensitive information.
To fix CVE-2017-1395, ensure that HTTP Strict Transport Security is properly enabled in your IBM Security Identity Governance and Intelligence Virtual Appliance.
CVE-2017-1395 affects versions 5.2 to 5.2.3.2 of the IBM Security Identity Governance and Intelligence Virtual Appliance.
CVE-2017-1395 can be exploited by a remote attacker who can gain access to the affected system.
CVE-2017-1395 can lead to the exposure of sensitive information due to inadequate security configurations.