First published: Thu Jan 11 2018(Updated: )
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Access Manager 9.0 Firmware | =9.0.0 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.0.1 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.1.0 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.2.0 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.2.1 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.3 | |
Ibm Security Access Manager 9.0 Firmware | =9.0.3.1 | |
IBM Security Access Manager | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1478.
The severity of CVE-2017-1478 is low with a severity value of 3.3.
IBM Security Access Manager Appliance versions 9.0.0, 9.0.0.1, 9.0.1.0, 9.0.2.0, 9.0.2.1, 9.0.3, and 9.0.3.1 are affected by CVE-2017-1478.
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system.
To fix CVE-2017-1478, upgrade to a patched version of IBM Security Access Manager Appliance.