CVE-2017-1396: High severity IBM Security Identity Governance and Intelligence vulnerability
Published Aug 6, 2018
·Updated
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342.
Affected Software
7 affected components
IBM Security Identity Governance and Intelligence=5.2
IBM Security Identity Governance and Intelligence=5.2.1
IBM Security Identity Governance and Intelligence=5.2.2
IBM Security Identity Governance and Intelligence=5.2.2.1
IBM Security Identity Governance and Intelligence=5.2.3
IBM Security Identity Governance and Intelligence=5.2.3.1
IBM Security Identity Governance and Intelligence=5.2.3.2
Remediation
Patch Available
Event History
Aug 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1396?
The severity of CVE-2017-1396 is high.
2
What is IBM Security Identity Governance Virtual Appliance affected by CVE-2017-1396?
IBM Security Identity Governance Virtual Appliance versions 5.2 through 5.2.3.2 are affected by CVE-2017-1396.
3
How does IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 vulnerability work?
This vulnerability allows unintended actors to read or modify a security-critical resource.
4
What is the Common Vulnerabilities and Exposures ID for this vulnerability?
CVE-2017-1396 is the Common Vulnerabilities and Exposures ID for this vulnerability.
5
Is there a fix available for CVE-2017-1396?
Yes, please refer to the IBM Security Identity Governance Virtual Appliance documentation for information on how to fix CVE-2017-1396.