CVE-2017-1478: Infoleak
Published Jan 11, 2018
·Updated
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.
Affected Software
8 affected components
IBM Security Access Manager 9.0 Firmware=9.0.0
IBM Security Access Manager 9.0 Firmware=9.0.0.1
IBM Security Access Manager 9.0 Firmware=9.0.1.0
IBM Security Access Manager 9.0 Firmware=9.0.2.0
IBM Security Access Manager 9.0 Firmware=9.0.2.1
IBM Security Access Manager 9.0 Firmware=9.0.3
IBM Security Access Manager 9.0 Firmware=9.0.3.1
IBM Security Access Manager=9.0
Remediation
Patch Available
Event History
Jan 11, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-1478.
2
What is the severity of CVE-2017-1478?
The severity of CVE-2017-1478 is low with a severity value of 3.3.
3
Which version of IBM Security Access Manager Appliance is affected by CVE-2017-1478?
IBM Security Access Manager Appliance versions 9.0.0, 9.0.0.1, 9.0.1.0, 9.0.2.0, 9.0.2.1, 9.0.3, and 9.0.3.1 are affected by CVE-2017-1478.
4
What is the vulnerability description of CVE-2017-1478?
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system.
5
How can I fix CVE-2017-1478?
To fix CVE-2017-1478, upgrade to a patched version of IBM Security Access Manager Appliance.