CVE-2017-1701: Weak Encryption
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 134393.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1701?
CVE-2017-1701 has been rated as a medium severity vulnerability due to the exposure of sensitive user credentials.
How do I fix CVE-2017-1701?
To mitigate CVE-2017-1701, upgrade your IBM Team Concert and IBM Collaborative Lifecycle Management software to the latest version that addresses this encryption weakness.
Who is affected by CVE-2017-1701?
Users of IBM Team Concert versions 5.0 through 6.0.5 and IBM Collaborative Lifecycle Management versions 5.0 through 6.0.5 are affected by CVE-2017-1701.
What type of information is vulnerable in CVE-2017-1701?
CVE-2017-1701 makes highly sensitive user credentials vulnerable due to the use of a weak encryption algorithm.
Can an authenticated user exploit CVE-2017-1701?
Yes, an authenticated user can exploit CVE-2017-1701 to gain access to sensitive information stored using weak encryption.