First published: Wed Sep 27 2017(Updated: )
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | =5.2 | |
IBM Security Identity Governance and Intelligence | =5.2.1 | |
IBM Security Identity Manager | =6.0.0.0 | |
IBM Security Identity Manager | =7.0.0.0 | |
IBM Security Privileged Identity Manager Virtual Appliance | =2.0 | |
IBM Security Privileged Identity Manager Virtual Appliance | =2.0.1 | |
IBM Security Privileged Identity Manager Virtual Appliance | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1483 has a high severity rating due to the impact of allowing unauthorized access to critical resources.
Fixing CVE-2017-1483 requires updating IBM Security Identity Manager and its adapters to the latest patched versions.
CVE-2017-1483 affects IBM Security Identity Manager versions 6.0.0.0 and 7.0.0.0, as well as versions of IBM Security Identity Governance and Intelligence and IBM Security Privileged Identity Manager.
CVE-2017-1483 allows anonymous users to access protected areas, potentially leading to data exposure and unauthorized actions.
Yes, CVE-2017-1483 can be easily exploited by removing or bypassing authentication checks.