First published: Thu Aug 03 2017(Updated: )
IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =9.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1504 is classified as a medium severity vulnerability.
CVE-2017-1504 can lead to weaker than expected security when using the PasswordUtil command for AES password encryption.
To mitigate CVE-2017-1504, upgrade to a fixed version of IBM WebSphere Application Server that addresses this vulnerability.
CVE-2017-1504 affects IBM WebSphere Application Server version 9.0.0.4.
Users should review their encryption practices and apply patches or updates that address the vulnerability in CVE-2017-1504.