CVE-2017-1693: Medium severity ibm integration bus for z/os vulnerability
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2017-1693.
What is the severity of CVE-2017-1693?
The severity of CVE-2017-1693 is medium with a CVSS score of 5.6.
Which software versions are affected by CVE-2017-1693?
CVE-2017-1693 affects IBM Integration Bus versions 9.0.0.0 to 9.0.0.8, and version 10.0.0.0 to 10.0.0.9.
How does the vulnerability in IBM Integration Bus 9.0 and 10.0 work?
The vulnerability allows an attacker with a captured valid session ID to hijack another user's session during a short time frame before the session expires.
How can I fix CVE-2017-1693?
To fix CVE-2017-1693, IBM recommends applying the necessary security fixes provided by the vendor and ensuring timely session timeouts to minimize the risk of session hijacking.