CVE-2017-1490: Infoleak
Published Sep 14, 2017
·Updated
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
Affected Software
5 affected components
IBM Jazz Reporting Service=6.0
IBM Jazz Reporting Service=6.0.1
IBM Jazz Reporting Service=6.0.2
IBM Jazz Reporting Service=6.0.3
IBM Jazz Reporting Service=6.0.4
Remediation
Patch Available
Event History
Sep 14, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1490?
CVE-2017-1490 is classified as a high severity vulnerability due to its potential to disclose sensitive information.
2
How do I fix CVE-2017-1490?
To remediate CVE-2017-1490, users should upgrade to a patched version of IBM Jazz Reporting Service that addresses the vulnerability.
3
Which versions of IBM Jazz Reporting Service are affected by CVE-2017-1490?
CVE-2017-1490 affects IBM Jazz Reporting Service versions 6.0 through 6.0.4.
4
What type of threat does CVE-2017-1490 present?
CVE-2017-1490 presents a threat of unauthorized information disclosure from the Lifecycle Query Engine.
5
Is there known exploitation of CVE-2017-1490?
As of the current date, there have been no publicly reported incidents of exploitation specifically tied to CVE-2017-1490.