CVE-2017-1694: High severity ibm integration bus for z/os vulnerability
Published Dec 20, 2017
·Updated
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
Affected Software
20 affected components
IBM Integration Bus=9.0.0.0
IBM Integration Bus=9.0.0.1
IBM Integration Bus=9.0.0.2
IBM Integration Bus=9.0.0.3
IBM Integration Bus=9.0.0.4
IBM Integration Bus=9.0.0.5
IBM Integration Bus=9.0.0.6
IBM Integration Bus=9.0.0.7
IBM Integration Bus=9.0.0.8
IBM Integration Bus=9.0.0.9
IBM Integration Bus=10.0.0.0
IBM Integration Bus=10.0.0.1
IBM Integration Bus=10.0.0.2
IBM Integration Bus=10.0.0.3
IBM Integration Bus=10.0.0.4
IBM Integration Bus=10.0.0.5
IBM Integration Bus=10.0.0.6
IBM Integration Bus=10.0.0.7
IBM Integration Bus=10.0.0.8
IBM Integration Bus=10.0.0.9
Event History
Dec 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2017-1694.
2
What is the severity level of CVE-2017-1694?
The severity level of CVE-2017-1694 is high with a severity value of 8.1.
3
What is the affected software for CVE-2017-1694?
The affected software for CVE-2017-1694 is IBM Integration Bus versions 9.0.0.0 to 9.0.0.9 and 10.0.0.0 to 10.0.0.9.
4
How does CVE-2017-1694 affect IBM Integration Bus?
CVE-2017-1694 allows an attacker to intercept and read user credentials in plain text when transmitted by IBM Integration Bus versions 9.0 and 10.0.
5
Is there a fix available for CVE-2017-1694?
Yes, IBM has provided security patches to address the vulnerability. Please refer to the IBM Security Bulletin for more information.