CVE-2017-1601: Critical severity ibm infosphere guardium database activity monitoring vulnerability
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1601?
CVE-2017-1601 has a medium severity rating due to the potential for user account compromise.
How do I fix CVE-2017-1601?
To fix CVE-2017-1601, ensure that strong password policies are enforced for all user accounts in IBM Security Guardium.
What versions of IBM Security Guardium are affected by CVE-2017-1601?
CVE-2017-1601 affects IBM Security Guardium versions 10.0, 10.0.1, and 10.1 through 10.1.4.
Who is affected by CVE-2017-1601?
Organizations using the affected versions of IBM Security Guardium may be vulnerable to account compromises.
What should I do if I cannot upgrade due to CVE-2017-1601?
If upgrading is not possible, implement strict password controls and monitoring to mitigate the risk from CVE-2017-1601.