First published: Mon Aug 06 2018(Updated: )
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | =5.2 | |
IBM Security Identity Governance and Intelligence | =5.2.1 | |
IBM Security Identity Governance and Intelligence | =5.2.2 | |
IBM Security Identity Governance and Intelligence | =5.2.2.1 | |
IBM Security Identity Governance and Intelligence | =5.2.3 | |
IBM Security Identity Governance and Intelligence | =5.2.3.1 | |
IBM Security Identity Governance and Intelligence | =5.2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1411 has a medium severity due to the lack of strong password requirements which can lead to account compromises.
To fix CVE-2017-1411, configure your IBM Security Identity Governance Virtual Appliance to enforce strong password policies.
CVE-2017-1411 affects versions 5.2 through 5.2.3.2 of IBM Security Identity Governance.
Yes, attackers can exploit CVE-2017-1411 easily due to the absence of strong password requirements.
CVE-2017-1411 poses a risk of unauthorized access to user accounts and potential data breaches.