CVE-2017-1412: Infoleak
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1412?
CVE-2017-1412 has been classified as a vulnerability of moderate severity due to the exposure of sensitive information.
How do I fix CVE-2017-1412?
To fix CVE-2017-1412, ensure that you update IBM Security Identity Governance Virtual Appliance to version 5.2.3.3 or later.
What types of information are exposed by CVE-2017-1412?
CVE-2017-1412 can expose sensitive information about the environment, users, or associated data through error messages.
Which versions are affected by CVE-2017-1412?
CVE-2017-1412 affects IBM Security Identity Governance Virtual Appliance versions 5.2 through 5.2.3.2.
Is there a workaround for CVE-2017-1412?
There is no official workaround for CVE-2017-1412, so patching is the recommended action.